CVE-2014-3327: Input Validation
The EnergyWise module in Cisco IOS 12.2, 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.2.xXO, 3.3.xSG, 3.4.xSG, and 3.5.xE before 3.5.3E allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 packet, aka Bug ID CSCup52101.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3327?
CVE-2014-3327 is rated as high severity due to its potential to cause denial of service through a device reload.
How do I fix CVE-2014-3327?
To mitigate CVE-2014-3327, you should upgrade to Cisco IOS versions 3.5.3E or later.
What systems are affected by CVE-2014-3327?
CVE-2014-3327 affects various Cisco IOS and IOS XE versions including 12.2, 15.0 through 15.4, and multiple 3.x revisions of IOS XE.
How does CVE-2014-3327 operate?
CVE-2014-3327 allows remote attackers to exploit the EnergyWise module by sending crafted IPv4 packets that cause device reloads.
Is there a workaround for CVE-2014-3327?
Currently, there is no documented workaround for CVE-2014-3327, therefore upgrading software is the recommended action.