CVE-2014-3269: Input Validation
Published May 20, 2014
·Updated
The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service (device reload) by polling frequently, aka Bug ID CSCug65204.
Affected Software
1 affected component
Cisco IOS XE=3.5e
Event History
May 20, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·11:13 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3269?
CVE-2014-3269 has been rated as a medium severity vulnerability due to its potential to cause a denial of service.
2
How does CVE-2014-3269 affect Cisco IOS XE 3.5E?
CVE-2014-3269 allows remote authenticated users to cause a denial of service by polling the SNMP module frequently.
3
Can CVE-2014-3269 be exploited without authentication?
No, CVE-2014-3269 requires remote authenticated access to exploit the vulnerability.
4
What are the impacts of CVE-2014-3269 on affected devices?
Affected devices may experience a denial of service, resulting in a device reload due to frequent SNMP polling.
5
How can I mitigate CVE-2014-3269 on my devices?
To mitigate CVE-2014-3269, limit SNMP polling frequency and consider upgrading to a patched version of Cisco IOS XE.