Lucene search

K
ciscoCiscoCISCO-SA-20141010-CVE-2014-3405
HistoryOct 10, 2014 - 8:53 p.m.

Cisco IOS XE Software Autonomic Networking Infrastructure Routing Protocol for Low-Power and Lossy Networks Vulnerability

2014-10-1020:53:29
tools.cisco.com
14

CVSS2

4.8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:P/A:P

EPSS

0.003

Percentile

65.6%

A vulnerability in the IPv6 Routing Protocol for Low-Power and Lossy Networks (RPL) of Cisco IOS XE could allow an unauthenticated, adjacent attacker to inject routes into the autonomic control plane (ACP).

The vulnerability is due to RPL being active on ACP as well as the external Autonomic Networking Infrastructure (ANI) interfaces. An attacker could exploit this vulnerability by sending crafted RPL advertisements to the ANI device.

Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.

To exploit this vulnerability, an attacker must be on the same broadcast or collision domain as the targeted device. This access requirement may reduce the possibility of a successful exploit.

Affected configurations

Vulners
Node
ciscocisco_iosMatch3.13sxe
OR
ciscocisco_iosMatch3.13.0sxe
VendorProductVersionCPE
ciscocisco_ios3.13scpe:2.3:o:cisco:cisco_ios:3.13s:xe:*:*:*:*:*:*
ciscocisco_ios3.13.0scpe:2.3:o:cisco:cisco_ios:3.13.0s:xe:*:*:*:*:*:*

CVSS2

4.8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:P/A:P

EPSS

0.003

Percentile

65.6%

Related for CISCO-SA-20141010-CVE-2014-3405