CVE-2014-0718: Input Validation
The produce-verbose-alert feature in Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of service (Analysis Engine process outage) via fragmented packets, aka Bug ID CSCui91266.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0718?
CVE-2014-0718 is classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2014-0718?
To fix CVE-2014-0718, upgrade the Cisco IPS Software to version 7.1(8)E4 or 7.2(2)E4 or later.
What environments are affected by CVE-2014-0718?
CVE-2014-0718 affects Cisco IPS Software versions 7.1(4)E4, 7.1(5)E4, 7.1(6)E4, 7.1(7)E4, and 7.2(1)E4.
What kind of attack is possible with CVE-2014-0718?
CVE-2014-0718 allows remote attackers to exploit fragmented packets to cause an outage in the Analysis Engine process.
Is there a workaround for CVE-2014-0718?
There are no specific workarounds for CVE-2014-0718; the recommended action is to apply the security updates provided by Cisco.