// For flags

CVE-2021-1615

Cisco Embedded Wireless Controller Software for Catalyst Access Points Denial of Service Vulnerability

Severity Score

8.6
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected AP. This vulnerability is due to insufficient buffer allocation. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to exhaust available resources and cause a DoS condition on an affected AP, as well as a DoS condition for client traffic traversing the AP.

Una vulnerabilidad en la funcionalidad packet processing de Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) podría permitir a un atacante remoto no autenticado causar una condición de denegación de servicio (DoS) en un AP afectado. Esta vulnerabilidad es debido a una asignación insuficiente del búfer. Un atacante podría explotar esta vulnerabilidad mediante el envío de tráfico diseñado a un dispositivo afectado. Una explotación con éxito podría permitir al atacante agotar los recursos disponibles y causar una condición de DoS en un AP afectado, así como una condición de DoS para el tráfico del cliente que atraviesa el AP

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2020-11-13 CVE Reserved
  • 2021-09-23 CVE Published
  • 2024-06-07 EPSS Updated
  • 2024-11-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-410: Insufficient Resource Pool
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Embedded Wireless Controller
Search vendor "Cisco" for product "Embedded Wireless Controller"
<= 17.6.1
Search vendor "Cisco" for product "Embedded Wireless Controller" and version " <= 17.6.1"
-
Affected
in Cisco
Search vendor "Cisco"
Catalyst 9105
Search vendor "Cisco" for product "Catalyst 9105"
--
Safe
Cisco
Search vendor "Cisco"
Embedded Wireless Controller
Search vendor "Cisco" for product "Embedded Wireless Controller"
<= 17.6.1
Search vendor "Cisco" for product "Embedded Wireless Controller" and version " <= 17.6.1"
-
Affected
in Cisco
Search vendor "Cisco"
Catalyst 9115
Search vendor "Cisco" for product "Catalyst 9115"
--
Safe
Cisco
Search vendor "Cisco"
Embedded Wireless Controller
Search vendor "Cisco" for product "Embedded Wireless Controller"
<= 17.6.1
Search vendor "Cisco" for product "Embedded Wireless Controller" and version " <= 17.6.1"
-
Affected
in Cisco
Search vendor "Cisco"
Catalyst 9117
Search vendor "Cisco" for product "Catalyst 9117"
--
Safe
Cisco
Search vendor "Cisco"
Embedded Wireless Controller
Search vendor "Cisco" for product "Embedded Wireless Controller"
<= 17.6.1
Search vendor "Cisco" for product "Embedded Wireless Controller" and version " <= 17.6.1"
-
Affected
in Cisco
Search vendor "Cisco"
Catalyst 9120
Search vendor "Cisco" for product "Catalyst 9120"
--
Safe
Cisco
Search vendor "Cisco"
Embedded Wireless Controller
Search vendor "Cisco" for product "Embedded Wireless Controller"
<= 17.6.1
Search vendor "Cisco" for product "Embedded Wireless Controller" and version " <= 17.6.1"
-
Affected
in Cisco
Search vendor "Cisco"
Catalyst 9124
Search vendor "Cisco" for product "Catalyst 9124"
--
Safe
Cisco
Search vendor "Cisco"
Embedded Wireless Controller
Search vendor "Cisco" for product "Embedded Wireless Controller"
<= 17.6.1
Search vendor "Cisco" for product "Embedded Wireless Controller" and version " <= 17.6.1"
-
Affected
in Cisco
Search vendor "Cisco"
Catalyst 9130
Search vendor "Cisco" for product "Catalyst 9130"
--
Safe