← Back

CVE-2021-40114

nvd nist
Published: Oct 27, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper memory resource management while the Snort detection engine is processing ICMP packets. An attacker could exploit this vulnerability by sending a series of ICMP packets through an affected device. A successful exploit could allow the attacker to exhaust resources on the affected device, causing the device to reload.

Affected (11)

3 products
Firepower Threat Defense
Secure Firewall Management Center
Unified Threat Defense
1 product
Snort
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Before 6.4.0.12
From 6.5.0 to 6.6.3
From 6.7.0 to 6.7.0.2
Cisco
Version 2.9.14.0
Version 2.9.15
Version 2.9.16
Version 2.9.17
Cisco
From 16.12 to 16.12.6
From 17.3 to 17.3.4a
From 17.4 to 17.4.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0.0 to 2.9.18

Timeline

No history available yet.