CVE-2014-3308: Input Validation
Published Jul 7, 2014
·Updated
Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted packets, aka Bug ID CSCun83985.
Affected Software
8 affected components
Cisco IOS XR
Cisco Asr 9000 Rsp440 Router
Cisco Asr 9001
Cisco Asr 9006
Cisco Asr 9010
Cisco Asr 9904
Cisco Asr 9912
Cisco Asr 9922
Event History
Jul 7, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3308?
CVE-2014-3308 is classified as a denial of service vulnerability that can significantly impact device performance.
2
How do I fix CVE-2014-3308?
To fix CVE-2014-3308, upgrade to the recommended patched versions of Cisco IOS XR as specified by Cisco.
3
What type of devices are affected by CVE-2014-3308?
CVE-2014-3308 affects Cisco ASR 9000 series devices running Cisco IOS XR.
4
What attack vector is used in CVE-2014-3308?
CVE-2014-3308 can be exploited remotely by sending specifically crafted packets to the affected devices.
5
What can be the potential consequences of CVE-2014-3308?
Exploitation of CVE-2014-3308 may lead to excessive CPU consumption, resulting in device instability or denial of service.