CVE-2021-34697 — Improper Initialization in Cisco IOS XE
Severity
8.6HIGHNVD
CNA5.8
EPSS
0.5%
top 35.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 23
Latest updateMay 24
Description
A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. This vulnerability is due to incorrect programming of the half-opened connections limit, TCP SYN flood limit, or TCP SYN cookie features when the features are configured in vulnerable releases of Cisco IOS XE Software. An attacker could exploit this vulnerabili…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-7jmp-v8mh-4f8r: A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remot↗2022-05-24
CVEList▶
Cisco IOS XE Software Protection Against Distributed Denial of Service Attacks Feature Vulnerability↗2021-09-23
📋Vendor Advisories
1Cisco▶
Cisco IOS XE Software Protection Against Distributed Denial of Service Attacks Feature Vulnerability↗2021-09-22