CVE-2014-2112: Input Validation
Published Mar 27, 2014
·Updated
The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP requests, aka Bug ID CSCuf51357.
Affected Software
4 affected components
Cisco IOS=15.1
Cisco IOS=15.2
Cisco IOS=15.3
Cisco IOS=15.4
Event History
Mar 27, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2112?
CVE-2014-2112 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2014-2112?
To mitigate CVE-2014-2112, it's recommended to upgrade your Cisco IOS to a version that addresses this vulnerability.
3
What systems are affected by CVE-2014-2112?
CVE-2014-2112 affects Cisco IOS versions 15.1 through 15.4.
4
What type of attack does CVE-2014-2112 involve?
CVE-2014-2112 involves denial of service attacks through crafted HTTP requests.
5
Is there a workaround for CVE-2014-2112?
There are no specified workarounds for CVE-2014-2112, the best defense is to apply the necessary updates.