CVE-2014-2111: Input Validation
The Application Layer Gateway (ALG) module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (device reload) via crafted DNS packets, aka Bug ID CSCue00996.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2111?
CVE-2014-2111 is classified as a high severity vulnerability due to its ability to cause a denial of service on affected devices.
How do I fix CVE-2014-2111?
To mitigate CVE-2014-2111, upgrade your Cisco IOS device to a version that addresses this vulnerability.
Which versions of Cisco IOS are affected by CVE-2014-2111?
CVE-2014-2111 affects Cisco IOS versions 12.2 through 12.4 and 15.0 through 15.4.
What is the impact of CVE-2014-2111?
The impact of CVE-2014-2111 is a denial of service that can lead to device reloads when processing specially crafted DNS packets.
Can CVE-2014-2111 be exploited remotely?
Yes, CVE-2014-2111 can be exploited remotely by attackers who send crafted DNS packets to the affected device.