First published: Thu Mar 20 2014(Updated: )
Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 devices, allows remote attackers to cause a denial of service (device crash) via crafted multicast packets, aka Bug ID CSCuf60783.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | <=15.1\(2\)sy3 | |
Cisco Catalyst 6500-E | ||
All of | ||
Cisco IOS | <=15.1\(2\)sy3 | |
Cisco Catalyst 6500-E |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2124 has been classified as a high severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2014-2124, upgrade to a Cisco IOS version later than 15.1(2)SY3.
CVE-2014-2124 affects Cisco IOS 15.1(2)SY3 and earlier versions running on Cisco Catalyst 6500 devices with Supervisor Engine 2T.
CVE-2014-2124 involves remote attackers sending crafted multicast packets that can crash the device.
Yes, CVE-2014-2124 can be exploited remotely, which means it is a critical concern for internet-facing devices.