CVE-2014-2108: Input Validation
Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.2 through 3.7 before 3.7.5S and 3.8 through 3.10 before 3.10.1S allow remote attackers to cause a denial of service (device reload) via a malformed IKEv2 packet, aka Bug ID CSCui88426.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2108?
CVE-2014-2108 has been classified as a high severity vulnerability due to its potential to cause a denial of service by reloading the affected device.
How do I fix CVE-2014-2108?
To fix CVE-2014-2108, you should upgrade affected Cisco IOS or IOS XE software to versions 12.2(33)SXH or later for IOS and 3.7.5S or later for IOS XE.
Which versions are affected by CVE-2014-2108?
CVE-2014-2108 affects Cisco IOS versions 12.2 to 15.3 and IOS XE versions 3.2 to 3.10 before specific patched versions.
What is the impact of CVE-2014-2108?
The impact of CVE-2014-2108 is that it allows remote attackers to send malformed IKEv2 packets, leading to a device reload and denial of service.
Is there a workaround for CVE-2014-2108?
There are no specific workarounds for CVE-2014-2108; the recommended action is to apply the necessary updates and patches.