LiveActive security incident?Get immediate response
CVE Record

CVE-2021-1424: Cisco ASR 5000 Series Software (StarOS) ipsecmgr Process Denial of Service Vulnerability

A vulnerability in the ipsecmgr process of Cisco ASR 5000 Series Software (StarOS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of incoming Internet Key Exchange Version 2 (IKEv2) packets. An attacker could exploit this vulnerability by sending specifically malformed IKEv2 packets to an affected device. A successful exploit could allow the attacker to cause the ipsecmgr process to restart, which would disrupt ongoing IKE negotiations and result in a temporary DoS condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

MediumCVSS 5.3Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This is a service disruption risk in Cisco ASR 5000 Series Software (StarOS). A remote unauthenticated attacker could send malformed IKEv2 traffic that makes the ipsecmgr process restart, temporarily interrupting ongoing IKE negotiations. The provided sources do not indicate data theft or system takeover.

Executive priority

Schedule remediation in the normal vulnerability cycle, with faster handling for carrier, VPN, or mobile-core services where IKE negotiation disruption affects customers. This is not a critical compromise scenario in the provided sources, but it can affect service availability.

Technical view

The flaw is insufficient validation of incoming IKEv2 packets in the StarOS ipsecmgr process, mapped to CWE-119. CVSS 3.1 is 5.3 with network attack vector, low complexity, no privileges, no user interaction, and low availability impact. Cisco says software updates are available and no workaround addresses it.

Likely exposure

Organizations are exposed if they operate Cisco ASR 5000 Series Software versions listed as affected and receive IKEv2/IPsec traffic on those systems. Internet or untrusted-network reachability increases operational risk. The source bundle does not identify other affected Cisco products.

Exploitation context

The source bundle supports remote unauthenticated denial of service through malformed IKEv2 packets. It does not state active exploitation, public exploit availability, or CISA KEV listing. Treat exploitation as plausible but not confirmed in the provided evidence.

Researcher notes

Focus validation on StarOS version, ipsecmgr exposure, and observed availability impact. Do not assume confidentiality or integrity impact beyond the CVSS vector. Cisco’s no-workaround statement makes patch verification the central remediation evidence.

Mitigation direction

  • Upgrade affected Cisco ASR 5000 Series Software using Cisco’s advisory guidance.
  • Prioritize systems that process IKEv2/IPsec traffic from untrusted networks.
  • Apply exposure reduction controls where operationally feasible until patched.
  • Monitor Cisco guidance because the advisory states there are no workarounds.

Validation and detection

  • Inventory Cisco ASR 5000 Series Software versions against Cisco’s affected version list.
  • Confirm whether ASR 5000 devices accept IKEv2 traffic from untrusted networks.
  • Review logs for unexpected ipsecmgr restarts or IKE negotiation interruptions.
  • Verify upgraded versions are listed by Cisco as fixed or not affected.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-119: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-1424 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.3 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/RL:X/RC:X/E:X

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
6Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.3CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/RL:X/RC:X/E:X3.91.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

5.3Medium
CVSS 3.1 vector shape for CVE-2021-1424Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/RL:X/RC:X/E:X

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
CiscoCisco ASR 5000 Series Software21.15.7, 21.13.10, 21.14.1, 21.11.5, 21.13.8, 21.14.5, 21.12.8, 21.13.11, 21.11.8, 21.12.9, 21.15.5, 21.11.7, 21.13.5, 21.12.0, 21.15.2, 21.11.6, 21.14.2, 21.12.3, 21.15.0, 21.11.2, 21.13.7, 21.12.4, 21.12.12, 21.13.4, 21.12.5, 21.14.a0, 21.11.9, 21.14.0, 21.11.4, 21.12.7, 21.14.3, 21.12.2, 21.14.10, 21.15.4, 21.14.6, 21.15.3, 21.13.13, 21.12.11, 21.12.10, 21.14.9, 21.11.1, 21.14.7, 21.11.3, 21.13.3, 21.13.2, 21.13.14, 21.12.1, 21.13.6, 21.13.12, 21.15.8, 21.13.1, 21.15.1, 21.15.6, 21.13.9, 21.14.4, 21.13.0, 21.12.6, 21.14.8, 21.11.0, 21.15.15, 21.14.11, 21.17.2, 21.15.13, 21.15.12, 21.14.b15, 21.17.0, 21.15.10, 21.13.16, 21.14.12, 21.15.20, 21.11.10, 21.15.18, 21.15.14, 21.13.15, 21.15.21, 21.15.17, 21.17.1, 21.14.b14, 21.12.13, 21.12.14, 21.15.19, 21.15.11, 21.15.22, 21.17.3, 21.14.b13, 21.15.16, 21.14.b12, 21.16.2, 21.14.16, 21.14.b17, 21.15.24, 21.16.c9, 21.15.25, 21.15.26, 21.16.d0, 21.17.4, 21.15.27, 21.13.17, 21.18.0, 21.15.28, 21.14.17, 21.16.d1, 21.18.1, 21.16.3, 21.14.b18, 21.16.c10, 21.11.11, 21.15.29, 21.15.30, 21.13.18, 21.12.16, 21.17.5, 21.16.c11, 21.15.32, 21.13.19, 21.15.33, 21.11.12, 21.19.0, 21.18.2, 21.14.19, 21.19.1, 21.17.6, 21.11.13, 21.12.17, 21.15.36, 21.18.3, 21.14.b19, 21.19.2, 21.15.37, 21.17.7, 21.14.20, 21.16.c12, 21.18.4, 21.19.3, 21.13.20, 21.15.40, 21.14.b20, 21.16.4, 21.18.5, 21.14.b21, 21.16.c13, 21.11.14, 21.12.18, 21.20.SV1, 21.20.0, 21.15.41, 21.20.SV2, 21.17.8, 21.20.1, 21.20.SV3, 21.16.5, 21.20.SV5, 21.15.43, 21.19.4, 21.18.6, 21.15.45, 21.20.2, 21.16.c14, 21.17.9, 21.11.15, 21.14.22, 21.20.3, 21.15.46, 21.18.7, 21.19.n3, 21.15.47, 21.15.48, 21.19.5, 21.17.10, 21.18.8, 21.16.6, 21.12.19, 21.13.21, 21.20.4, 21.18.9, 21.19.n4, 21.17.11, 21.18.11, 21.19.6, 21.16.c15, 21.16.7, 21.17.12, 21.21.0, 21.17.13, 21.11.16, 21.12.20, 21.18.12, 21.12.21, 21.14.b22, 21.19.7, 21.20.6, 21.18.13, 21.19.n5, 21.18.14, 21.20.7, 21.11.17, 21.17.14, 21.19.8, 21.20.8, 21.19.9, 21.17.15, 21.20.9, 21.18.15, 21.15.51, 21.14.23, 21.19.10, 21.20.k6, 21.11.18, 21.19.n6, 21.16.8, 21.15.52, 21.17.16, 21.20.10, 21.15.53, 21.11.19, 21.20.k7, 21.15.54, 21.20.11, 21.20.u8, 21.21.1, 21.17.17, 21.15.55unknown
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-119 · source CWE mapping

Improper Restriction of Operations within the Bounds of a Memory Buffer

Improper Restriction of Operations within the Bounds of a Memory Buffer represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.