CVE-2014-0677: Input Validation
Published Jan 22, 2014
·Updated
The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service (temporary LDP session outage) via LDP discovery traffic containing malformed Hello messages, aka Bug ID CSCul88851.
Affected Software
1 affected component
Cisco NX-OS
Event History
Jan 22, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What traffic must an attacker send to exploit this issue?
An attacker must send LDP discovery traffic containing malformed Hello messages. The resulting impact is a temporary outage of the LDP session.
2
Does exploitation require authentication or prior access?
No. The provided vector identifies the issue as network-accessible with low attack complexity and no authentication requirement.