First published: Sun May 25 2014(Updated: )
Cisco IOS XE on ASR1000 devices, when PPPoE termination is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed PPPoE packet, aka Bug ID CSCuo55180.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE | ||
Cisco ASR 1001 | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1013 | ||
Cisco ASR 1023 Router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3284 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2014-3284, update your Cisco IOS XE or ASR1000 device software to the latest version that addresses this vulnerability.
CVE-2014-3284 affects Cisco IOS XE on ASR1000 devices, including models ASR 1001, 1002, 1004, 1006, 1013, and 1023.
CVE-2014-3284 allows remote attackers to send malformed PPPoE packets causing the device to reload, resulting in a denial of service.
Disabling PPPoE termination on the affected Cisco devices can serve as an immediate workaround until the vulnerability is patched.