CVE-2021-1356
Last modified
CVE-2021-1356 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient error handling in the web UI. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient error handling in the web UI. An attacker could exploit these vulnerabilities by sending crafted HTTP packets to an affected device. A successful exploit could allow the attacker to cause the web UI software to become unresponsive and consume all available vty lines, preventing new session establishment and resulting in a DoS condition. Manual intervention would be required to regain web UI and vty session functionality. Note: These vulnerabilities do not affect the console connection.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 3.15.1xbs |
| Cisco | Ios Xe | 3.15.2xbs |
| Cisco | Ios Xe | 17.1.1 |
| Cisco | Ios Xe | 17.1.1a |
| Cisco | Ios Xe | 17.1.1s |
| Cisco | Ios Xe | 17.1.1t |
| Cisco | Ios Xe | 17.1.2 |
| Cisco | Ios Xe | 17.2.1 |
| Cisco | Ios Xe | 17.2.1a |
| Cisco | Ios Xe | 17.2.1r |
| Cisco | Ios Xe | 17.2.1v |
| Cisco | Ios Xe | 17.2.2 |
| Cisco | Ios Xe | 17.2.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-1356?
How severe is CVE-2021-1356?
How do I fix CVE-2021-1356?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-1350A vulnerability in the web UI of Cisco Umbrella could allow …5.3
- CVE-2021-1351A vulnerability in the web-based interface of Cisco Webex Me…6.1
- CVE-2021-1352A vulnerability in the DECnet Phase IV and DECnet/OSI protoc…6.5
- CVE-2021-1353A vulnerability in the IPv4 protocol handling of Cisco StarO…8.6
- CVE-2021-1354A vulnerability in the certificate registration process of C…3.5
- CVE-2021-1355Multiple vulnerabilities in Cisco Unified Communications Man…6.5
- CVE-2021-1357Multiple vulnerabilities in Cisco Unified Communications Man…6.5
- CVE-2021-1358A vulnerability in the web-based management interface of Cis…6.1
- CVE-2021-1359A vulnerability in the configuration management of Cisco Asy…8.8
- CVE-2021-1360Multiple vulnerabilities in the web-based management interfa…7.2
- CVE-2021-1361A vulnerability in the implementation of an internal file ma…9.1
- CVE-2021-1362A vulnerability in the SOAP API endpoint of Cisco Unified Co…8.8
Are you affected by CVE-2021-1356?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
