CVE-2021-1625Improper Access Control in Cisco IOS XE

Severity
5.8MEDIUMNVD
EPSS
0.4%
top 40.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 23
Latest updateMay 24

Description

A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists because ICMP and UDP responder-to-initiator flows are not inspected when the Zone-Based Policy Firewall has either Unified Threat Defense (UTD) or Application Quality of Experience (AppQoE) configured. An attacker could exploit this vulnerability by attempting to s

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDcisco/ios_xe< 17.3.2

🔴Vulnerability Details

2
GHSA
GHSA-w3v7-hj7c-4j8f: A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone2022-05-24
CVEList
Cisco IOS XE Software Zone-Based Policy Firewall ICMP and UDP Inspection Vulnerability2021-09-23

📋Vendor Advisories

1
Cisco
Cisco IOS XE Software Zone-Based Policy Firewall ICMP and UDP Inspection Vulnerability2021-09-22
CVE-2021-1625 — Improper Access Control in Cisco IOS XE | cvebase