First published: Thu Mar 27 2014(Updated: )
Cisco IOS 12.2 and 15.0 through 15.3, when used with the Kailash FPGA before 2.6 on RSP720-3C-10GE and RSP720-3CXL-10GE devices, allows remote attackers to cause a denial of service (route switch processor outage) via crafted IP packets, aka Bug ID CSCug84789.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =12.2 | |
Cisco IOS | =15.0 | |
Cisco IOS | =15.0\(1\)se | |
Cisco IOS | =15.1 | |
Cisco IOS | =15.2 | |
Cisco IOS | =15.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2107 has a critical severity rating due to its potential to cause a denial of service on affected devices.
To fix CVE-2014-2107, upgrade to a Cisco IOS version that is not affected by this vulnerability.
CVE-2014-2107 affects Cisco IOS versions 12.2 and 15.0 through 15.3 running on RSP720-3C-10GE and RSP720-3CXL-10GE devices.
Yes, CVE-2014-2107 can be exploited remotely, allowing attackers to craft specific IP packets to trigger the vulnerability.
CVE-2014-2107 enables denial of service attacks that can lead to outages of the route switch processor.