CVE-2021-1620Assignment to Variable without Use in Cisco IOS

Severity
7.7HIGHNVD
EPSS
0.3%
top 43.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 23
Latest updateMay 24

Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. This vulnerability occurs because the code does not release the allocated IP address under certain failure conditions. An attacker could exploit this vulnerability by trying to connect to the device with a non-AnyConnect client. A successful

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 3.1 | Impact: 4.0

Affected Packages3 packages

NVDcisco/ios412 versions+411
NVDcisco/ios_xe277 versions+276
CVEListV5cisco/cisco_iosn/a

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hj64-pmxg-fcx3: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software c2022-05-24
CVEList
Cisco IOS and IOS XE Software IKEv2 AutoReconnect Feature Denial of Service Vulnerability2021-09-23

💥Exploits & PoCs

2
Exploit-DB
DLINK DAP-1620 A1 v1.01 - Directory Traversal2022-05-11
Nuclei
D-Link DAP-1620 - Local File Inclusion

📋Vendor Advisories

1
Cisco
Cisco IOS and IOS XE Software IKEv2 AutoReconnect Feature Denial of Service Vulnerability2021-09-22
CVE-2021-1620 — Assignment to Variable without Use | cvebase