CVE-2014-3295: Medium severity Cisco NX-OS vulnerability
The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3295?
CVE-2014-3295 has a significant severity rating due to its potential to allow unauthorized access and denial of service on affected Cisco NX-OS devices.
How do I fix CVE-2014-3295?
To fix CVE-2014-3295, upgrade to a patched version of Cisco NX-OS that addresses the vulnerability.
Who is affected by CVE-2014-3295?
CVE-2014-3295 affects multiple versions of Cisco NX-OS, including versions up to and including 6.2(2a).
What types of attacks can exploit CVE-2014-3295?
CVE-2014-3295 can be exploited through malformed HSRP packets, leading to authentication bypass and denial of service.
Is there a workaround for CVE-2014-3295?
There is no effective workaround for CVE-2014-3295, and upgrading to a secure version is strongly recommended.