LiveActive security incident?Get immediate response
CVE Record

CVE-2021-34697: Cisco IOS XE Software Protection Against Distributed Denial of Service Attacks Feature Vulnerability

A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. This vulnerability is due to incorrect programming of the half-opened connections limit, TCP SYN flood limit, or TCP SYN cookie features when the features are configured in vulnerable releases of Cisco IOS XE Software. An attacker could exploit this vulnerability by attempting to flood traffic to or through the affected device. A successful exploit could allow the attacker to initiate a DoS attack to or through an affected device.

MediumCVSS 5.8Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This Cisco IOS XE issue can let an unauthenticated remote attacker degrade availability of an affected network device or traffic passing through it. The risk is operational disruption, not data theft. Exposure depends on running vulnerable IOS XE releases with specific Protection Against DDoS features configured.

Executive priority

Prioritize remediation where IOS XE devices protect internet-facing or business-critical paths. This is not a critical data compromise issue, but it can affect availability of network services and should be addressed through normal vulnerability management with faster handling for exposed edge infrastructure.

Technical view

The vulnerability is in IOS XE Protection Against Distributed Denial of Service features. Incorrect programming of half-open connection limits, TCP SYN flood limits, or TCP SYN cookies can allow traffic flooding to cause a denial of service to or through the device. CVSS is 5.8, network-accessible, low complexity, no privileges, availability impact only.

Likely exposure

Most relevant to Cisco IOS XE devices that are reachable by untrusted traffic and have the affected Protection Against DDoS features configured. The source bundle does not provide exact vulnerable version ranges, so exposure requires checking device software and configuration against Cisco’s advisory.

Exploitation context

The bundle does not show CISA KEV listing or cited active exploitation. Exploitation is remote and unauthenticated, but described only as flooding traffic to or through an affected device. No exploit steps or public exploit evidence are provided in the supplied sources.

Researcher notes

Key uncertainty is version scope: the bundle lists Cisco IOS XE Software but does not include exact affected releases or fixed versions. The technical trigger is configuration-dependent and tied to specific Protection Against DDoS controls, so validation should combine software inventory with configuration review.

Mitigation direction

  • Use Cisco’s advisory to identify affected and fixed IOS XE releases.
  • Upgrade affected IOS XE devices according to Cisco guidance.
  • Prioritize perimeter, internet-facing, and high-throughput transit devices.
  • If upgrade is delayed, request Cisco-approved workarounds or compensating controls.
  • Monitor affected devices for abnormal SYN flood or connection-limit behavior.

Validation and detection

  • Inventory Cisco IOS XE devices and record software releases.
  • Check whether half-open limits, SYN flood limits, or SYN cookies are configured.
  • Compare versions and configuration against Cisco advisory cisco-sa-zbfw-tguGuYq.
  • Review network monitoring for availability degradation during traffic floods.
  • Confirm remediation by rechecking version and relevant feature configuration.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-665: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-34697 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.8CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L3.91.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

5.8Medium
CVSS 3.1 vector shape for CVE-2021-34697Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
CiscoCisco IOS XE Softwaren/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-665 · source CWE mapping

Improper Initialization

Improper Initialization represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.