First published: Thu Sep 25 2014(Updated: )
The ALG module in Cisco IOS 15.0 through 15.4 does not properly implement SIP over NAT, which allows remote attackers to cause a denial of service (device reload) via multipart SDP IPv4 traffic, aka Bug ID CSCun54071.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =15.0 | |
Cisco IOS | =15.1 | |
Cisco IOS | =15.2 | |
Cisco IOS | =15.3 | |
Cisco IOS | =15.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3361 is classified as a moderate severity vulnerability that can lead to device reloads.
To fix CVE-2014-3361, upgrade your Cisco IOS to a version higher than 15.4 that addresses this vulnerability.
CVE-2014-3361 affects Cisco IOS versions 15.0 through 15.4 specifically related to SIP over NAT.
Exploiting CVE-2014-3361 can result in a denial of service condition causing the affected device to reload.
CVE-2014-3361 can be exploited by remote attackers sending specific multipart SDP IPv4 traffic.