CVE-2014-3361: Buffer Overflow
Published Sep 25, 2014
·Updated
The ALG module in Cisco IOS 15.0 through 15.4 does not properly implement SIP over NAT, which allows remote attackers to cause a denial of service (device reload) via multipart SDP IPv4 traffic, aka Bug ID CSCun54071.
Affected Software
5 affected components
Cisco IOS=15.0
Cisco IOS=15.1
Cisco IOS=15.2
Cisco IOS=15.3
Cisco IOS=15.4
Event History
Sep 25, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3361?
CVE-2014-3361 is classified as a moderate severity vulnerability that can lead to device reloads.
2
How do I fix CVE-2014-3361?
To fix CVE-2014-3361, upgrade your Cisco IOS to a version higher than 15.4 that addresses this vulnerability.
3
What does CVE-2014-3361 affect?
CVE-2014-3361 affects Cisco IOS versions 15.0 through 15.4 specifically related to SIP over NAT.
4
What is the impact of exploiting CVE-2014-3361?
Exploiting CVE-2014-3361 can result in a denial of service condition causing the affected device to reload.
5
Who can exploit CVE-2014-3361?
CVE-2014-3361 can be exploited by remote attackers sending specific multipart SDP IPv4 traffic.