CVE-2021-1622 describes a denial-of-service vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers. An unauthenticated, remote attacker can exploit a deadlock condition by sending high-burst COPS packets, leading to resource exhaustion and a DoS. This vulnerability has a CVSS score of 8.6 (High), indicating a critical risk due to its network-based attack vector, low attack complexity, and high impact on availability. A successful exploit prevents control plane processes from obtaining necessary resources. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.12.1z1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* | ||
17.3.1xCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:17.3.1x:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.