CVE-2014-3357: OS Command Injection
Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allow remote attackers to cause a denial of service (device reload) via malformed mDNS packets, aka Bug ID CSCul90866.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3357?
CVE-2014-3357 has a severity rating of high due to its potential to cause remote denial of service attacks.
How do I fix CVE-2014-3357?
To mitigate CVE-2014-3357, upgrade to a non-vulnerable version of Cisco IOS or IOS XE.
Which Cisco IOS versions are affected by CVE-2014-3357?
CVE-2014-3357 affects Cisco IOS versions 15.0, 15.1, 15.2, and 15.4, as well as specific versions of IOS XE.
What types of attacks can CVE-2014-3357 enable?
CVE-2014-3357 can enable remote attackers to launch denial of service attacks by sending malformed mDNS packets.
Is there a workaround for CVE-2014-3357?
There are no effective workarounds for CVE-2014-3357; the only solution is to update to a secure version.