CVE-2021-1288
published 2021-02-04CVE-2021-1288: Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.95%
78.0th percentile
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xr_software | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | >= 5.0.0 < 5.2.6 | 5.2.6 |
| cisco | ios_xr | >= 5.3.0 < 5.3.4 | 5.3.4 |
| cisco | ios_xr | >= 6.0.0 < 6.0.2 | 6.0.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.6HIGH
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-75j3-4jfq-x36j: Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a
ghsa_unreviewed·2022-05-24
CVE-2021-1288 [HIGH] GHSA-75j3-4jfq-x36j: Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Red Hat
python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling
vendor_redhat·2026-06-22·CVSS 5.9
CVE-2026-53538 [MEDIUM] CWE-1288 python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling
python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form fields past an upstream body inspecting component. This vulnerability is fixed in 0.0.30.
A flaw was found in Python-Multipart, a tool used for processing web form data. A remote attacker co
Cisco
Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
vendor_cisco·2021-02-03·CVSS 8.6
CVE-2021-1288 [HIGH] CWE-399 Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dos-WwDdghs2
Cisco
Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1288 Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
CVE-2021-1288: Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-399, CWE-399
Bug IDs: CSCuy67256, CSCuz39742, CSCuz39742, CSCuy67256, CSCuz39742
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-04
Published