First published: Thu Sep 25 2014(Updated: )
Memory leak in Cisco IOS 15.1 through 15.4 and IOS XE 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S; and 3.11.xS before 3.12S allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed DHCPv6 packets, aka Bug ID CSCum90081.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =15.1 | |
Cisco IOS | =15.2 | |
Cisco IOS | =15.3 | |
Cisco IOS | =15.4 | |
Cisco IOS XE Software | =3.4.0s | |
Cisco IOS XE Software | =3.4.1s | |
Cisco IOS XE Software | =3.4.2s | |
Cisco IOS XE Software | =3.4.3s | |
Cisco IOS XE Software | =3.4.4s | |
Cisco IOS XE Software | =3.4.5s | |
Cisco IOS XE Software | =3.5.0s | |
Cisco IOS XE Software | =3.5.1s | |
Cisco IOS XE Software | =3.5.2s | |
Cisco IOS XE Software | =3.6s\(.0\) | |
Cisco IOS XE Software | =3.6s\(.1\) | |
Cisco IOS XE Software | =3.6s\(.2\) | |
Cisco IOS XE Software | =3.7\(0\)s | |
Cisco IOS XE Software | =3.7\(1\)as | |
Cisco IOS XE Software | =3.7\(2\)s | |
Cisco IOS XE Software | =3.7\(3\)s | |
Cisco IOS XE Software | =3.7\(4\)s | |
Cisco IOS XE Software | =3.7\(5\)s | |
Cisco IOS XE Software | =3.8.0s | |
Cisco IOS XE Software | =3.8s\(.0\) | |
Cisco IOS XE Software | =3.8s\(.1\) | |
Cisco IOS XE Software | =3.8s\(.2\) | |
Cisco IOS XE Software | =3.9s\(.0\) | |
Cisco IOS XE Software | =3.9s\(.1\) | |
Cisco IOS XE Software | =3.9s\(.2\) | |
Cisco IOS XE Software | =3.10 | |
Cisco IOS XE Software | =3.10.0s | |
Cisco IOS XE Software | =3.11.0s | |
Cisco IOS XE Software | =3.11.1s | |
Cisco IOS XE Software | =3.11.2s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3359 is classified as a high severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2014-3359, upgrade to a patched version of Cisco IOS or IOS XE that addresses this vulnerability.
CVE-2014-3359 allows remote attackers to execute denial of service attacks by sending malformed DHCPv6 packets.
CVE-2014-3359 affects Cisco IOS versions 15.1 through 15.4 and specific IOS XE versions from 3.4.xS to 3.11.xS.
While there is no public information indicating active exploitation of CVE-2014-3359, it is recommended to apply fixes promptly due to its high severity.