First published: Thu Mar 27 2014(Updated: )
Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.2 through 3.7 before 3.7.5S and 3.8 through 3.10 before 3.10.1S allow remote attackers to cause a denial of service (device reload) via a malformed IKEv2 packet, aka Bug ID CSCui88426.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =12.2 | |
Cisco IOS | =15.0 | |
Cisco IOS | =15.0\(1\)se | |
Cisco IOS | =15.1 | |
Cisco IOS | =15.2 | |
Cisco IOS | =15.3 | |
Cisco IOS XE | =3.2.0s | |
Cisco IOS XE | =3.2.0sg | |
Cisco IOS XE | =3.2.0xo | |
Cisco IOS XE | =3.2.1s | |
Cisco IOS XE | =3.2.1sg | |
Cisco IOS XE | =3.2.2s | |
Cisco IOS XE | =3.2.2sg | |
Cisco IOS XE | =3.2.3sg | |
Cisco IOS XE | =3.2.4sg | |
Cisco IOS XE | =3.2s\(.0\) | |
Cisco IOS XE | =3.2s\(.1\) | |
Cisco IOS XE | =3.2s\(.2\) | |
Cisco IOS XE | =3.3.0s | |
Cisco IOS XE | =3.3.0sg | |
Cisco IOS XE | =3.3.1s | |
Cisco IOS XE | =3.3.1sg | |
Cisco IOS XE | =3.3.2s | |
Cisco IOS XE | =3.3.3s | |
Cisco IOS XE | =3.3s\(.0\) | |
Cisco IOS XE | =3.3s\(.1\) | |
Cisco IOS XE | =3.3s\(.2\) | |
Cisco IOS XE | =3.4.0as | |
Cisco IOS XE | =3.4.0s | |
Cisco IOS XE | =3.4.1s | |
Cisco IOS XE | =3.4.2s | |
Cisco IOS XE | =3.4.3s | |
Cisco IOS XE | =3.4.4s | |
Cisco IOS XE | =3.4.5s | |
Cisco IOS XE | =3.4.xs | |
Cisco IOS XE | =3.4s\(.0\) | |
Cisco IOS XE | =3.4s\(.1\) | |
Cisco IOS XE | =3.4s\(.2\) | |
Cisco IOS XE | =3.4s\(.3\) | |
Cisco IOS XE | =3.4s\(.4\) | |
Cisco IOS XE | =3.4s\(.5\) | |
Cisco IOS XE | =3.4s\(.6\) | |
Cisco IOS XE | =3.5.0s | |
Cisco IOS XE | =3.5.1s | |
Cisco IOS XE | =3.5.2s | |
Cisco IOS XE | =3.5.xs | |
Cisco IOS XE | =3.5s\(.0\) | |
Cisco IOS XE | =3.5s\(.1\) | |
Cisco IOS XE | =3.5s\(.2\) | |
Cisco IOS XE | =3.6.0s | |
Cisco IOS XE | =3.6.1s | |
Cisco IOS XE | =3.6.2s | |
Cisco IOS XE | =3.6s\(.0\) | |
Cisco IOS XE | =3.6s\(.1\) | |
Cisco IOS XE | =3.6s\(.2\) | |
Cisco IOS XE | =3.7.0s | |
Cisco IOS XE | =3.7.1s | |
Cisco IOS XE | =3.7.2s | |
Cisco IOS XE | =3.7s\(.0\) | |
Cisco IOS XE | =3.7s\(.1\) | |
Cisco IOS XE | =3.8.0s | |
Cisco IOS XE | =3.8s\(.0\) | |
Cisco IOS XE | =3.8s\(.1\) | |
Cisco IOS XE | =3.8s\(.2\) | |
Cisco IOS XE | =3.9.0s | |
Cisco IOS XE | =3.9.1s | |
Cisco IOS XE | =3.10 | |
=12.2 | ||
=15.0 | ||
=15.0\(1\)se | ||
=15.1 | ||
=15.2 | ||
=15.3 | ||
=3.2.0s | ||
=3.2.0sg | ||
=3.2.0xo | ||
=3.2.1s | ||
=3.2.1sg | ||
=3.2.2s | ||
=3.2.2sg | ||
=3.2.3sg | ||
=3.2.4sg | ||
=3.2s\(.0\) | ||
=3.2s\(.1\) | ||
=3.2s\(.2\) | ||
=3.3.0s | ||
=3.3.0sg | ||
=3.3.1s | ||
=3.3.1sg | ||
=3.3.2s | ||
=3.3.3s | ||
=3.3s\(.0\) | ||
=3.3s\(.1\) | ||
=3.3s\(.2\) | ||
=3.4.0as | ||
=3.4.0s | ||
=3.4.1s | ||
=3.4.2s | ||
=3.4.3s | ||
=3.4.4s | ||
=3.4.5s | ||
=3.4.xs | ||
=3.4s\(.0\) | ||
=3.4s\(.1\) | ||
=3.4s\(.2\) | ||
=3.4s\(.3\) | ||
=3.4s\(.4\) | ||
=3.4s\(.5\) | ||
=3.4s\(.6\) | ||
=3.5.0s | ||
=3.5.1s | ||
=3.5.2s | ||
=3.5.xs | ||
=3.5s\(.0\) | ||
=3.5s\(.1\) | ||
=3.5s\(.2\) | ||
=3.6.0s | ||
=3.6.1s | ||
=3.6.2s | ||
=3.6s\(.0\) | ||
=3.6s\(.1\) | ||
=3.6s\(.2\) | ||
=3.7.0s | ||
=3.7.1s | ||
=3.7.2s | ||
=3.7s\(.0\) | ||
=3.7s\(.1\) | ||
=3.8.0s | ||
=3.8s\(.0\) | ||
=3.8s\(.1\) | ||
=3.8s\(.2\) | ||
=3.9.0s | ||
=3.9.1s | ||
=3.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2108 has been classified as a high severity vulnerability due to its potential to cause a denial of service by reloading the affected device.
To fix CVE-2014-2108, you should upgrade affected Cisco IOS or IOS XE software to versions 12.2(33)SXH or later for IOS and 3.7.5S or later for IOS XE.
CVE-2014-2108 affects Cisco IOS versions 12.2 to 15.3 and IOS XE versions 3.2 to 3.10 before specific patched versions.
The impact of CVE-2014-2108 is that it allows remote attackers to send malformed IKEv2 packets, leading to a device reload and denial of service.
There are no specific workarounds for CVE-2014-2108; the recommended action is to apply the necessary updates and patches.