CVE-2014-2109: Input Validation
Published Mar 27, 2014
·Updated
The TCP Input module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted TCP packets, aka Bug IDs CSCuh33843 and CSCuj41494.
Affected Software
8 affected components
Cisco IOS=12.2
Cisco IOS=12.3
Cisco IOS=12.4
Cisco IOS=15.0
Cisco IOS=15.1
Cisco IOS=15.2
Cisco IOS=15.3
Cisco IOS=15.4
Event History
Mar 27, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2109?
CVE-2014-2109 has a high severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2014-2109?
To fix CVE-2014-2109, upgrade to a patched version of Cisco IOS that addresses the vulnerability.
3
What are the affected versions for CVE-2014-2109?
CVE-2014-2109 affects Cisco IOS versions 12.2 through 12.4 and 15.0 through 15.4.
4
What type of attack does CVE-2014-2109 involve?
CVE-2014-2109 involves denial of service attacks through crafted TCP packets.
5
Can CVE-2014-2109 cause device reloads?
Yes, CVE-2014-2109 can lead to memory consumption issues or device reloads.