CVE-2014-2201: Null Pointer Dereference
The Message Transfer Service (MTS) in Cisco NX-OS before 6.2(7) on MDS 9000 devices and 6.0 before 6.0(2) on Nexus 7000 devices allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a large volume of crafted traffic, aka Bug ID CSCtw98915.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2201?
CVE-2014-2201 has a high severity rating due to its potential to cause a denial of service on affected devices.
How do I fix CVE-2014-2201?
To fix CVE-2014-2201, upgrade to Cisco NX-OS version 6.2(7) or later on MDS 9000 devices and version 6.0(2) or later on Nexus 7000 devices.
What devices are affected by CVE-2014-2201?
CVE-2014-2201 affects Cisco NX-OS versions prior to 6.2(7) on MDS 9000 devices and versions prior to 6.0(2) on Nexus 7000 devices.
Can CVE-2014-2201 be exploited remotely?
Yes, CVE-2014-2201 can be exploited remotely through crafted traffic that leads to a kernel panic.
What actions should I take if I am using affected Cisco products related to CVE-2014-2201?
If using affected Cisco products, it is critical to immediately apply recommended software updates to mitigate the risk associated with CVE-2014-2201.