First published: Wed Nov 26 2014(Updated: )
Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XRv 9000 | <=5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8005 has a high severity rating due to its potential to cause a denial of service.
To mitigate CVE-2014-8005, users should upgrade Cisco IOS XR to a version later than 5.1.0.
CVE-2014-8005 specifically affects Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices.
CVE-2014-8005 allows remote attackers to exploit a race condition to establish many TCP sessions resulting in a denial of service.
There are no confirmed workarounds for CVE-2014-8005, and upgrading is the recommended solution.