CVE-2021-1616
A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass the ALG. This vulnerability is due to insufficient data validation of traffic that is traversing the ALG. An attacker could exploit this vulnerability by sending crafted traffic to a targeted device. A successful exploit could allow the attacker to bypass the ALG and open connections that should not be allowed to a remote device located behind the ALG. Note: This vulnerability has been publicly discussed as NAT Slipstreaming.
EPSS 0.58% · 69.4th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | ios_xe | 0 |
| Cisco | Cisco IOS XE Software | n/a |
Exploit Intelligence
Timeline
- Sep 23, 2021 EPSS Score
- Sep 23, 2021 CVE Published
- Nov 19, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Mar 14, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 10, 2022 EPSS Score
- Jul 6, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 26, 2022 EPSS Score
- Feb 21, 2023 EPSS Score
- Mar 7, 2023 EPSS Score