First published: Sat Apr 05 2014(Updated: )
Cisco IOS XR does not properly throttle ICMPv6 redirect packets, which allows remote attackers to cause a denial of service (IPv4 and IPv6 transit outage) via crafted redirect messages, aka Bug ID CSCum14266.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XRv 9000 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2144 has been classified as a high-severity vulnerability due to its potential to cause denial of service.
To mitigate CVE-2014-2144, users should apply the recommended patches and updates provided by Cisco for impacted versions of IOS XR.
CVE-2014-2144 affects Cisco IOS XR software versions that do not properly throttle ICMPv6 redirect packets.
Yes, CVE-2014-2144 can be exploited remotely by an attacker sending crafted ICMPv6 redirect messages.
CVE-2014-2144 can lead to both IPv4 and IPv6 transit outages, severely impacting network performance and availability.