Lucene search

K
cveCiscoCVE-2014-3357
HistorySep 25, 2014 - 10:55 a.m.

CVE-2014-3357

2014-09-2510:55:08
CWE-78
cisco
web.nvd.nist.gov
29
cisco
ios
ios xe
denial of service
mdns
vulnerability
cve-2014-3357

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.8

Confidence

High

EPSS

0.012

Percentile

84.9%

Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allow remote attackers to cause a denial of service (device reload) via malformed mDNS packets, aka Bug ID CSCul90866.

Affected configurations

Nvd
Node
ciscoiosMatch15.0
OR
ciscoiosMatch15.1
OR
ciscoiosMatch15.2
OR
ciscoiosMatch15.4
OR
ciscoios_xeMatch3.3\(.0\)xo
OR
ciscoios_xeMatch3.3.0se
OR
ciscoios_xeMatch3.3.1se
OR
ciscoios_xeMatch3.5.0e
OR
ciscoios_xeMatch3.5.1e
OR
ciscoios_xeMatch3.11.0s
VendorProductVersionCPE
ciscoios15.0cpe:2.3:o:cisco:ios:15.0:*:*:*:*:*:*:*
ciscoios15.1cpe:2.3:o:cisco:ios:15.1:*:*:*:*:*:*:*
ciscoios15.2cpe:2.3:o:cisco:ios:15.2:*:*:*:*:*:*:*
ciscoios15.4cpe:2.3:o:cisco:ios:15.4:*:*:*:*:*:*:*
ciscoios_xe3.3(.0)xocpe:2.3:o:cisco:ios_xe:3.3\(.0\)xo:*:*:*:*:*:*:*
ciscoios_xe3.3.0secpe:2.3:o:cisco:ios_xe:3.3.0se:*:*:*:*:*:*:*
ciscoios_xe3.3.1secpe:2.3:o:cisco:ios_xe:3.3.1se:*:*:*:*:*:*:*
ciscoios_xe3.5.0ecpe:2.3:o:cisco:ios_xe:3.5.0e:*:*:*:*:*:*:*
ciscoios_xe3.5.1ecpe:2.3:o:cisco:ios_xe:3.5.1e:*:*:*:*:*:*:*
ciscoios_xe3.11.0scpe:2.3:o:cisco:ios_xe:3.11.0s:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.8

Confidence

High

EPSS

0.012

Percentile

84.9%