CVE-2014-2144: Input Validation
Cisco IOS XR does not properly throttle ICMPv6 redirect packets, which allows remote attackers to cause a denial of service (IPv4 and IPv6 transit outage) via crafted redirect messages, aka Bug ID CSCum14266.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2144?
CVE-2014-2144 has been classified as a high-severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2014-2144?
To mitigate CVE-2014-2144, users should apply the recommended patches and updates provided by Cisco for impacted versions of IOS XR.
What systems are affected by CVE-2014-2144?
CVE-2014-2144 affects Cisco IOS XR software versions that do not properly throttle ICMPv6 redirect packets.
Can CVE-2014-2144 be exploited remotely?
Yes, CVE-2014-2144 can be exploited remotely by an attacker sending crafted ICMPv6 redirect messages.
What impact does CVE-2014-2144 have on network performance?
CVE-2014-2144 can lead to both IPv4 and IPv6 transit outages, severely impacting network performance and availability.