CVE-2014-3353: High severity cisco ios xrv 9000 vulnerability
Published Sep 4, 2014
·Updated
Cisco IOS XR 4.3(.2) and earlier, as used in Cisco Carrier Routing System (CRS), allows remote attackers to cause a denial of service (CPU consumption and IPv6 packet drops) via a malformed IPv6 packet, aka Bug ID CSCuo95165.
Affected Software
3 affected components
Cisco IOS XR<=4.3.2
Cisco IOS XR=4.3.0
Cisco IOS XR=4.3.1
Event History
Sep 4, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3353?
CVE-2014-3353 is categorized as a denial of service vulnerability which could lead to significant service disruptions.
2
How do I fix CVE-2014-3353?
To mitigate CVE-2014-3353, upgrade Cisco IOS XR to version 4.3.3 or later to address the vulnerability.
3
Who is affected by CVE-2014-3353?
CVE-2014-3353 affects all Cisco Carrier Routing Systems running IOS XR versions 4.3.2 and earlier.
4
What type of attacks can CVE-2014-3353 enable?
CVE-2014-3353 can be exploited by remote attackers to cause high CPU utilization and drop IPv6 packets.
5
Is there a workaround for CVE-2014-3353?
There are no official workarounds for CVE-2014-3353, so upgrading to a secure version is recommended.