CVE-2014-2183: Input Validation
Published Apr 29, 2014
·Updated
The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP packet, aka Bug ID CSCun09973.
Affected Software
26 affected components
Cisco IOS XE<=3.10.2s
Cisco IOS XE=3.10
Cisco IOS XE=3.10.0s
Cisco IOS XE=3.10.1s
Cisco IOS XE=3.10.1s1
Cisco Asr 1001
Cisco Asr 1002
Cisco Asr 1002-x
Cisco Asr 1002 Fixed Router
Cisco Asr 1004
Cisco Asr 1006
Cisco Asr 1013
Cisco Asr 1023 Router
All of the following
Any of the following
Cisco IOS XE<=3.10.2s
Cisco IOS XE=3.10
Cisco IOS XE=3.10.0s
Cisco IOS XE=3.10.1s
Cisco IOS XE=3.10.1s1
Any of the following
Cisco Asr 1001
Cisco Asr 1002
Cisco Asr 1002-x
Cisco Asr 1002 Fixed Router
Cisco Asr 1004
Cisco Asr 1006
Cisco Asr 1013
Cisco Asr 1023 Router
Event History
Apr 29, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:37 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2183?
CVE-2014-2183 has a high severity rating as it allows for denial of service on affected Cisco ASR 1000 routers.
2
How do I fix CVE-2014-2183?
To fix CVE-2014-2183, upgrade to a supported version of Cisco IOS XE that is not vulnerable to this issue.
3
Which systems are affected by CVE-2014-2183?
CVE-2014-2183 affects Cisco IOS XE versions 3.10S(.2) and earlier on ASR 1000 series routers.
4
What type of attack does CVE-2014-2183 enable?
CVE-2014-2183 enables a denial-of-service attack through the sending of malformed L2TP packets.
5
Who can exploit CVE-2014-2183?
CVE-2014-2183 can be exploited by remote authenticated users targeting vulnerable Cisco devices.