CVE-2021-1377
Last modified
CVE-2021-1377 is a medium-severity vulnerability rated 5.8/10 on the CVSS scale. A vulnerability in Address Resolution Protocol (ARP) management of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent an affected device from resolving ARP entries for legitimate hosts on the connected subnets. This vulnerability exists because ARP entries are mismanaged. EPSS estimates a 1.43% chance of exploitation in the next 30 days.
Description
A vulnerability in Address Resolution Protocol (ARP) management of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent an affected device from resolving ARP entries for legitimate hosts on the connected subnets. This vulnerability exists because ARP entries are mismanaged. An attacker could exploit this vulnerability by continuously sending traffic that results in incomplete ARP entries. A successful exploit could allow the attacker to cause ARP requests on the device to be unsuccessful for legitimate hosts, resulting in a denial of service (DoS) condition.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.2\(6\)i1 |
| Cisco | Ios | 15.1\(3\)svr1 |
| Cisco | Ios | 15.1\(3\)svr2 |
| Cisco | Ios | 15.1\(3\)svr3 |
| Cisco | Ios | 15.1\(3\)svs |
| Cisco | Ios | 15.1\(3\)svs1 |
| Cisco | Ios | 15.2\(2\)e6 |
| Cisco | Ios | 15.2\(2\)e7 |
| Cisco | Ios | 15.2\(2\)e7b |
| Cisco | Ios | 15.2\(2\)e8 |
| Cisco | Ios | 15.2\(2\)e9 |
| Cisco | Ios | 15.2\(2\)e9a |
| Cisco | Ios | 15.2\(2\)e10 |
| Cisco | Ios | 15.2\(3\)e5 |
| Cisco | Ios | 15.2\(4\)e4 |
| Cisco | Ios | 15.2\(4\)e5 |
| Cisco | Ios | 15.2\(4\)e5a |
| Cisco | Ios | 15.2\(4\)e6 |
| Cisco | Ios | 15.2\(4\)e7 |
| Cisco | Ios | 15.2\(4\)e8 |
| Cisco | Ios | 15.2\(4\)e9 |
| Cisco | Ios | 15.2\(4\)e10 |
| Cisco | Ios | 15.2\(4\)e10a |
| Cisco | Ios | 15.2\(4\)ea6 |
| Cisco | Ios | 15.2\(4\)ea7 |
| Cisco | Ios | 15.2\(4\)ea8 |
| Cisco | Ios | 15.2\(4\)ea9 |
| Cisco | Ios | 15.2\(4\)ea9a |
| Cisco | Ios | 15.2\(4\)ea10 |
| Cisco | Ios | 15.2\(5\)e1 |
| Cisco | Ios | 15.2\(5\)e2 |
| Cisco | Ios | 15.2\(5\)e2b |
| Cisco | Ios | 15.2\(5\)e2c |
| Cisco | Ios | 15.2\(5\)ex |
| Cisco | Ios | 15.2\(5a\)e1 |
| Cisco | Ios | 15.2\(6\)e |
| Cisco | Ios | 15.2\(6\)e0a |
| Cisco | Ios | 15.2\(6\)e0c |
| Cisco | Ios | 15.2\(6\)e1 |
| Cisco | Ios | 15.2\(6\)e1a |
| Cisco | Ios | 15.2\(6\)e1s |
| Cisco | Ios | 15.2\(6\)e2 |
| Cisco | Ios | 15.2\(6\)e2a |
| Cisco | Ios | 15.2\(6\)e2b |
| Cisco | Ios | 15.2\(6\)e3 |
| Cisco | Ios | 15.2\(6\)eb |
| Cisco | Ios | 15.2\(7\)e |
| Cisco | Ios | 15.2\(7\)e0a |
| Cisco | Ios | 15.2\(7\)e0b |
| Cisco | Ios | 15.2\(7\)e0s |
Showing 50 of 302 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-1377?
How severe is CVE-2021-1377?
How do I fix CVE-2021-1377?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-1371A vulnerability in the role-based access control of Cisco IO…6.6
- CVE-2021-1372A vulnerability in Cisco Webex Meetings Desktop App and Webe…5.5
- CVE-2021-1373A vulnerability in the Control and Provisioning of Wireless …8.6
- CVE-2021-1374A vulnerability in the web-based management interface of Cis…4.8
- CVE-2021-1375Multiple vulnerabilities in the fast reload feature of Cisco…6.7
- CVE-2021-1376Multiple vulnerabilities in the fast reload feature of Cisco…6.7
- CVE-2021-1378A vulnerability in the SSH service of the Cisco StarOS opera…7.5
- CVE-2021-1379Multiple vulnerabilities in the Cisco Discovery Protoco…6.5
- CVE-2021-1380Multiple vulnerabilities in the web-based management interfa…6.1
- CVE-2021-1381A vulnerability in Cisco IOS XE Software could allow an auth…6.1
- CVE-2021-1382A vulnerability in the CLI of Cisco IOS XE SD-WAN Software c…6.7
- CVE-2021-1383Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN S…6.7
Are you affected by CVE-2021-1377?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
