CVE-2014-3335: Input Validation
Published Aug 26, 2014
·Updated
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of service (chip and card hangs) via a crafted packet, aka Bug ID CSCup77750.
Affected Software
10 affected components
Cisco IOS XR<=4.3.2
Cisco IOS XR=4.3.0
Cisco IOS XR=4.3.1
Cisco Asr 9000 Rsp440 Router
Cisco Asr 9001
Cisco Asr 9006
Cisco Asr 9010
Cisco Asr 9904
Cisco Asr 9912
Cisco Asr 9922
Event History
Aug 26, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
Is CVE-2014-3335 a remote exploit?
Yes, CVE-2014-3335 can be exploited remotely by sending crafted packets targeting the affected Cisco devices.