LiveActive security incident?Get immediate response
CVE Record

CVE-2021-1268: Cisco IOS XR Software IPv6 Flood Denial of Service Vulnerability

A vulnerability in the IPv6 protocol handling of the management interfaces of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause an IPv6 flood on the management interface network of an affected device. The vulnerability exists because the software incorrectly forwards IPv6 packets that have an IPv6 node-local multicast group address destination and are received on the management interfaces. An attacker could exploit this vulnerability by connecting to the same network as the management interfaces and injecting IPv6 packets that have an IPv6 node-local multicast group address destination. A successful exploit could allow the attacker to cause an IPv6 flood on the corresponding network. Depending on the number of Cisco IOS XR Software nodes on that network segment, exploitation could cause excessive network traffic, resulting in network degradation or a denial of service (DoS) condition.

HighCVSS 7.4Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2021-1268 can let someone on the same management network trigger excessive IPv6 traffic against Cisco IOS XR devices. The main business risk is loss or degradation of management-plane network availability, especially where many IOS XR nodes share the same segment.

Executive priority

Treat this as a high-priority availability risk for network infrastructure management. Urgency depends on whether untrusted systems can reach IOS XR management networks and how many affected nodes share a segment.

Technical view

Cisco IOS XR Software incorrectly forwards IPv6 packets with an IPv6 node-local multicast group destination when received on management interfaces. An unauthenticated adjacent attacker could inject such traffic and cause an IPv6 flood on the management-interface network, potentially resulting in degradation or denial of service.

Likely exposure

Exposure is most likely where Cisco IOS XR management interfaces are connected to networks reachable by untrusted or weakly controlled adjacent systems, and where IPv6 is present on those management segments. Larger shared management segments could experience greater traffic impact.

Exploitation context

The source bundle does not show CISA KEV listing or other evidence of active exploitation. Exploitation requires adjacency to the management-interface network and does not require authentication or user interaction.

Researcher notes

The public description supports adjacent, unauthenticated DoS via IPv6 handling on management interfaces. It does not provide affected version detail in the bundle. Validate exposure through inventory, network adjacency, IPv6 presence, and Cisco advisory mapping.

Mitigation direction

  • Review the Cisco advisory for affected releases, workarounds, and fixed software guidance.
  • Prioritize vendor-recommended updates for exposed Cisco IOS XR management networks.
  • Restrict management-interface network access to trusted administrative systems where feasible.
  • Segment management networks to limit blast radius between IOS XR nodes.
  • Monitor management segments for abnormal IPv6 multicast traffic or flooding.

Validation and detection

  • Inventory Cisco IOS XR devices and their management-interface network placement.
  • Check whether IPv6 is enabled or present on management-interface segments.
  • Confirm untrusted systems cannot join the same management network segment.
  • Review network telemetry for unusual IPv6 node-local multicast volume.
  • Map deployed IOS XR versions against the Cisco advisory.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-1076: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-1268 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.4 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.4CVSS 3.1HighCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H2.84Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

7.4High
CVSS 3.1 vector shape for CVE-2021-1268Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
CiscoCisco IOS XR Softwaren/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-1076 · source CWE mapping

Insufficient Adherence to Expected Conventions

Insufficient Adherence to Expected Conventions represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.