Lucene search

K
cveCiscoCVE-2014-3295
HistoryJun 14, 2014 - 4:26 a.m.

CVE-2014-3295

2014-06-1404:26:47
CWE-287
cisco
web.nvd.nist.gov
26
cve-2014-3295
cisco
nx-os
hsrp
authentication bypass
denial of service
cscup11309
vulnerability

CVSS2

4.8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:P/A:P

AI Score

7.1

Confidence

High

EPSS

0.006

Percentile

78.3%

The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.

Affected configurations

Nvd
Node
cisconx-osRange6.2\(2a\)
OR
cisconx-osMatch4.1.\(2\)
OR
cisconx-osMatch4.1.\(3\)
OR
cisconx-osMatch4.1.\(4\)
OR
cisconx-osMatch4.1.\(5\)
OR
cisconx-osMatch4.2\(3\)
OR
cisconx-osMatch4.2\(4\)
OR
cisconx-osMatch4.2\(6\)
OR
cisconx-osMatch4.2\(8\)
OR
cisconx-osMatch4.2.\(2a\)
OR
cisconx-osMatch5.0\(2a\)
OR
cisconx-osMatch5.0\(3\)
OR
cisconx-osMatch5.0\(5\)
OR
cisconx-osMatch5.1\(1a\)
OR
cisconx-osMatch5.1\(3\)
OR
cisconx-osMatch5.1\(4\)
OR
cisconx-osMatch5.1\(5\)
OR
cisconx-osMatch5.1\(6\)
OR
cisconx-osMatch5.2\(1\)
OR
cisconx-osMatch5.2\(3a\)
OR
cisconx-osMatch5.2\(4\)
OR
cisconx-osMatch5.2\(5\)
OR
cisconx-osMatch5.2\(7\)
OR
cisconx-osMatch5.2\(9\)
OR
cisconx-osMatch6.0\(1\)
OR
cisconx-osMatch6.0\(2\)
OR
cisconx-osMatch6.0\(3\)
OR
cisconx-osMatch6.0\(4\)
OR
cisconx-osMatch6.1\(1\)
OR
cisconx-osMatch6.1\(2\)
OR
cisconx-osMatch6.1\(3\)
OR
cisconx-osMatch6.1\(4\)
OR
cisconx-osMatch6.1\(4a\)
OR
cisconx-osMatch6.2\(2\)
VendorProductVersionCPE
cisconx-os*cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:*
cisconx-os4.1.(2)cpe:2.3:o:cisco:nx-os:4.1.\(2\):*:*:*:*:*:*:*
cisconx-os4.1.(3)cpe:2.3:o:cisco:nx-os:4.1.\(3\):*:*:*:*:*:*:*
cisconx-os4.1.(4)cpe:2.3:o:cisco:nx-os:4.1.\(4\):*:*:*:*:*:*:*
cisconx-os4.1.(5)cpe:2.3:o:cisco:nx-os:4.1.\(5\):*:*:*:*:*:*:*
cisconx-os4.2(3)cpe:2.3:o:cisco:nx-os:4.2\(3\):*:*:*:*:*:*:*
cisconx-os4.2(4)cpe:2.3:o:cisco:nx-os:4.2\(4\):*:*:*:*:*:*:*
cisconx-os4.2(6)cpe:2.3:o:cisco:nx-os:4.2\(6\):*:*:*:*:*:*:*
cisconx-os4.2(8)cpe:2.3:o:cisco:nx-os:4.2\(8\):*:*:*:*:*:*:*
cisconx-os4.2.(2a)cpe:2.3:o:cisco:nx-os:4.2.\(2a\):*:*:*:*:*:*:*
Rows per page:
1-10 of 341

CVSS2

4.8

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:P/A:P

AI Score

7.1

Confidence

High

EPSS

0.006

Percentile

78.3%