Lucene search

K
ciscoCiscoCISCO-SA-20140806-ENERGYWISE
HistoryAug 06, 2014 - 4:00 p.m.

Cisco IOS Software and Cisco IOS XE Software EnergyWise Crafted Packet Denial of Service Vulnerability

2014-08-0616:00:00
tools.cisco.com
15

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.009

Percentile

82.3%

A vulnerability in the EnergyWise module of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of the affected device.

The vulnerability is due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted EnergyWise packet to be processed by an affected device. An exploit could allow the attacker to cause a reload of the affected device.

Cisco has released software updates that address this vulnerability.

There are no workarounds for this vulnerability.

This advisory is available at the following link:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140806-energywise[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140806-energywise”]

Affected configurations

Vulners
Node
ciscoiosMatch12.2se
OR
ciscoiosMatch12.2ex
OR
ciscoiosMatch12.2ey
OR
ciscoiosMatch12.2ez
OR
ciscoiosMatch15.0se
OR
ciscoiosMatch15.1sg
OR
ciscoiosMatch15.0ex
OR
ciscoiosMatch15.1sy
OR
ciscoiosMatch15.2e
OR
ciscoiosMatch15.0ez
OR
ciscoiosMatch15.2sc
OR
ciscoiosMatch15.0ej
OR
ciscoiosMatch15.0ek
OR
ciscocisco_iosMatch3.7sxe
OR
ciscocisco_iosMatch3.3sgxe
OR
ciscocisco_iosMatch3.3xoxe
OR
ciscocisco_iosMatch3.4sgxe
OR
ciscocisco_iosMatch3.5exe
OR
ciscocisco_iosMatch3.10sxe
OR
ciscocisco_iosMatch3.12sxe
OR
ciscocisco_iosMatch3.6exe
OR
ciscoiosMatch12.2\(58\)se
OR
ciscoiosMatch12.2\(58\)se1
OR
ciscoiosMatch12.2\(58\)se2
OR
ciscoiosMatch12.2\(55\)ex3
OR
ciscoiosMatch12.2\(58\)ex
OR
ciscoiosMatch12.2\(58\)ey
OR
ciscoiosMatch12.2\(58\)ey1
OR
ciscoiosMatch12.2\(58\)ey2
OR
ciscoiosMatch12.2\(58\)ez
OR
ciscoiosMatch12.2\(60\)ez
OR
ciscoiosMatch12.2\(60\)ez1
OR
ciscoiosMatch12.2\(60\)ez2
OR
ciscoiosMatch12.2\(60\)ez3
OR
ciscoiosMatch12.2\(60\)ez4
OR
ciscoiosMatch12.2\(60\)ez5
OR
ciscoiosMatch15.0\(1\)se
OR
ciscoiosMatch15.0\(2\)se
OR
ciscoiosMatch15.0\(1\)se1
OR
ciscoiosMatch15.0\(1\)se2
OR
ciscoiosMatch15.0\(1\)se3
OR
ciscoiosMatch15.0\(2\)se1
OR
ciscoiosMatch15.0\(2\)se2
OR
ciscoiosMatch15.0\(2\)se3
OR
ciscoiosMatch15.0\(2\)se4
OR
ciscoiosMatch15.0\(2\)se5
OR
ciscoiosMatch15.0\(2\)se6
OR
ciscoiosMatch15.1\(1\)sg
OR
ciscoiosMatch15.1\(2\)sg
OR
ciscoiosMatch15.1\(1\)sg1
OR
ciscoiosMatch15.1\(1\)sg2
OR
ciscoiosMatch15.1\(2\)sg1
OR
ciscoiosMatch15.1\(2\)sg2
OR
ciscoiosMatch15.1\(2\)sg3
OR
ciscoiosMatch15.1\(2\)sg4
OR
ciscoiosMatch15.0\(2\)ex
OR
ciscoiosMatch15.0\(2\)ex1
OR
ciscoiosMatch15.0\(2\)ex2
OR
ciscoiosMatch15.0\(2\)ex3
OR
ciscoiosMatch15.0\(2\)ex4
OR
ciscoiosMatch15.0\(2\)ex5
OR
ciscoiosMatch15.0\(2\)ex6
OR
ciscoiosMatch15.1\(1\)sy
OR
ciscoiosMatch15.1\(1\)sy1
OR
ciscoiosMatch15.1\(2\)sy
OR
ciscoiosMatch15.1\(2\)sy1
OR
ciscoiosMatch15.1\(2\)sy2
OR
ciscoiosMatch15.1\(1\)sy2
OR
ciscoiosMatch15.1\(1\)sy3
OR
ciscoiosMatch15.1\(2\)sy3
OR
ciscoiosMatch15.2\(1\)e
OR
ciscoiosMatch15.2\(2\)e
OR
ciscoiosMatch15.2\(1\)e1
OR
ciscoiosMatch15.2\(1\)e2
OR
ciscoiosMatch15.2\(1\)e3
OR
ciscoiosMatch15.0\(2\)ez
OR
ciscoiosMatch15.2\(2\)sc3
OR
ciscoiosMatch15.0\(2\)ej
OR
ciscoiosMatch15.0\(2\)ej1
OR
ciscoiosMatch15.0\(2\)ek
OR
ciscoiosMatch15.0\(2\)ek1
OR
ciscocisco_iosMatch3.7.7sxe
OR
ciscocisco_iosMatch3.3.0sgxe
OR
ciscocisco_iosMatch3.3.2sgxe
OR
ciscocisco_iosMatch3.3.1sgxe
OR
ciscocisco_iosMatch3.3.0xoxe
OR
ciscocisco_iosMatch3.3.1xoxe
OR
ciscocisco_iosMatch3.3.2xoxe
OR
ciscocisco_iosMatch3.4.0sgxe
OR
ciscocisco_iosMatch3.4.2sgxe
OR
ciscocisco_iosMatch3.4.1sgxe
OR
ciscocisco_iosMatch3.4.3sgxe
OR
ciscocisco_iosMatch3.4.4sgxe
OR
ciscocisco_iosMatch3.5.0exe
OR
ciscocisco_iosMatch3.5.1exe
OR
ciscocisco_iosMatch3.5.2exe
OR
ciscocisco_iosMatch3.5.3exe
OR
ciscocisco_iosMatch3.10.4sxe
OR
ciscocisco_iosMatch3.12.0asxe
OR
ciscocisco_iosMatch3.6.0exe
OR
ciscocisco_iosMatch3.6.0aexe
VendorProductVersionCPE
ciscoios12.2secpe:2.3:o:cisco:ios:12.2se:*:*:*:*:*:*:*
ciscoios12.2excpe:2.3:o:cisco:ios:12.2ex:*:*:*:*:*:*:*
ciscoios12.2eycpe:2.3:o:cisco:ios:12.2ey:*:*:*:*:*:*:*
ciscoios12.2ezcpe:2.3:o:cisco:ios:12.2ez:*:*:*:*:*:*:*
ciscoios15.0secpe:2.3:o:cisco:ios:15.0se:*:*:*:*:*:*:*
ciscoios15.1sgcpe:2.3:o:cisco:ios:15.1sg:*:*:*:*:*:*:*
ciscoios15.0excpe:2.3:o:cisco:ios:15.0ex:*:*:*:*:*:*:*
ciscoios15.1sycpe:2.3:o:cisco:ios:15.1sy:*:*:*:*:*:*:*
ciscoios15.2ecpe:2.3:o:cisco:ios:15.2e:*:*:*:*:*:*:*
ciscoios15.0ezcpe:2.3:o:cisco:ios:15.0ez:*:*:*:*:*:*:*
Rows per page:
1-10 of 1011

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.009

Percentile

82.3%

Related for CISCO-SA-20140806-ENERGYWISE