CVE-2014-3290: Medium severity Cisco IOS XE vulnerability
The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the network or overwrite networking-services data via a crafted mDNS response, aka Bug ID CSCun64867.
Affected Software
Event History
Frequently Asked Questions
What network position does an attacker need to exploit this issue?
An attacker must be able to sniff the network to obtain sensitive networking-services information, or send a crafted mDNS response to overwrite networking-services data. The attack vector is adjacent-network access and does not require authentication.
Which deployments are affected?
The provided information identifies Cisco IOS XE 3.12S and specifically its mDNS interaction with autonomic networking. It does not state whether mDNS or autonomic networking is enabled by default.
What is the potential impact?
An attacker may obtain sensitive networking-services information through network sniffing or alter networking-services data by supplying a crafted mDNS response. The listed severity is medium, with partial confidentiality and integrity impact and no availability impact.