CVE-2014-3358: OS Command Injection
Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allows remote attackers to cause a denial of service (memory consumption, and interface queue wedge or device reload) via malformed mDNS packets, aka Bug ID CSCuj58950.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3358?
CVE-2014-3358 is categorized as a denial of service vulnerability that can lead to significant disruption in affected Cisco devices.
How do I fix CVE-2014-3358?
To mitigate CVE-2014-3358, update the affected Cisco IOS or IOS XE software to the latest recommended version that contains the security patch.
Which Cisco IOS versions are affected by CVE-2014-3358?
CVE-2014-3358 affects Cisco IOS versions 15.0 through 15.4 and several specific IOS XE versions.
What potential impact does CVE-2014-3358 have on network devices?
CVE-2014-3358 can lead to high memory consumption, causing device reloads and the possibility of interface queue wedges.
Can CVE-2014-3358 be exploited remotely?
Yes, CVE-2014-3358 can be exploited by remote attackers through malformed mDNS packets.