CVE-2021-1313
published 2021-02-04CVE-2021-1313: Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.95%
78.1th percentile
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xr_software | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | >= 5.0.0 < 5.2.6 | 5.2.6 |
| cisco | ios_xr | >= 5.3.0 < 5.3.4 | 5.3.4 |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rf6c-ww9j-gx78: Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a
ghsa_unreviewed·2022-05-24
CVE-2021-1313 [HIGH] CWE-401 GHSA-rf6c-ww9j-gx78: Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Chrome
Stable Channel Update for Desktop: CVE-2022-1313
vendor_chrome·2022-04-11·CVSS 8.8
CVE-2022-1313 [MEDIUM] Stable Channel Update for Desktop: CVE-2022-1313
Stable Channel Update for Desktop
CVE-2022-1313: Use after free in tab groups. Reported by Thomas Orlita on 2021-11-16 [$TBD][ 1304658 ] Medium CVE-2022-1314: Type Confusion in V8
Reported by Bohan Liu (@P4nda20371774) and exp-sky of Tencent Security Xuanwu Lab on 2022-03-09 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel
Severity: medium
Cisco
Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
vendor_cisco·2021-02-03·CVSS 8.6
CVE-2021-1288 [HIGH] CWE-399 Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dos-WwDdghs2
Cisco
Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1313 Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
CVE-2021-1313: Cisco IOS XR Software Enf Broker Denial of Service Vulnerability
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-399, CWE-399
Bug IDs: CSCuy67256, CSCuz39742, CSCuz39742, CSCuy67256, CSCuz39742
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14335 foreman: world-readable OMAPI secret through the ISC DHCP server
bugzilla·2020-07-17·CVSS 5.5
CVE-2020-14335 [MEDIUM] CVE-2020-14335 foreman: world-readable OMAPI secret through the ISC DHCP server
CVE-2020-14335 foreman: world-readable OMAPI secret through the ISC DHCP server
Red Hat Satellite 6 allows local user of Smart-Proxy system to read OMAPI interface secret. Local user using the ISC DHCP server can read object mapping API (OMAPI) secret, as by default it listens on all interfaces for OMAPI interfaction.
Discussion:
Mitigation:
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
---
Acknowledgments:
Name: Foreman
Upstream: Peter Bray (illumino Pty Ltd, Australia)
---
This issue has been addressed in the following products:
Red Hat Satellite 6.8 for RHEL 7
Via RHSA-2021:1313 https://acce
Bugzilla
CVE-2017-2662 foreman: Managing repositories with their id via hammer does not respect the role filters
bugzilla·2017-03-20·CVSS 4.3
CVE-2017-2662 [MEDIUM] CVE-2017-2662 foreman: Managing repositories with their id via hammer does not respect the role filters
CVE-2017-2662 foreman: Managing repositories with their id via hammer does not respect the role filters
Brad Buckingham of Red Hat reports:
After settings a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.
External reference:
http://projects.theforeman.org/issues/18838
Discussion:
Acknowledgments:
Name: Brad Buckingham (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Satellite 6.8 for RHEL 7
Via RHSA-2021:1313 https://access.redhat.com/errata/RHSA-2021:1313
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2017-
2021-02-04
Published