CVE-2014-3354: Input Validation
Cisco IOS 12.0, 12.2, 12.4, 15.0, 15.1, 15.2, and 15.3 and IOS XE 2.x and 3.x before 3.7.4S; 3.2.xSE and 3.3.xSE before 3.3.2SE; 3.3.xSG and 3.4.xSG before 3.4.4SG; and 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S allow remote attackers to cause a denial of service (device reload) via malformed RSVP packets, aka Bug ID CSCui11547.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3354?
CVE-2014-3354 is classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2014-3354?
Fixing CVE-2014-3354 involves updating affected Cisco IOS and IOS XE software to a version that includes the security patches.
What are the affected versions in CVE-2014-3354?
CVE-2014-3354 affects Cisco IOS versions 12.0, 12.2, 12.4, 15.0, 15.1, 15.2, 15.3, and several versions of IOS XE.
What is the impact of CVE-2014-3354?
The impact of CVE-2014-3354 is that remote attackers can exploit it to reload the affected Cisco devices, causing a denial of service.
Are there any workarounds for CVE-2014-3354?
Workarounds for CVE-2014-3354 may include disabling RSVP on affected devices, but applying patches is the recommended mitigation.