CVE-2011-3295: Input Validation
The NETIO and IPV4IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing System and other products, allow remote attackers to cause a denial of service (CPU consumption) via crafted network traffic, aka Bug ID CSCti59888.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3295?
CVE-2011-3295 is classified as a denial of service vulnerability that can lead to significant CPU consumption.
How do I fix CVE-2011-3295?
To mitigate CVE-2011-3295, upgrade to a fixed version of Cisco IOS XR as specified in Cisco's security advisories.
Which Cisco products are affected by CVE-2011-3295?
CVE-2011-3295 affects various versions of Cisco IOS XR including versions from 3.8 through the 4.1 series.
Can CVE-2011-3295 be exploited remotely?
Yes, CVE-2011-3295 can be exploited remotely by attackers using crafted network traffic.
What are the symptoms of a CVE-2011-3295 attack?
The main symptom of an attack exploiting CVE-2011-3295 is increased CPU usage leading to potential service interruptions.