CVE-2014-2108Improper Input Validation in Cisco IOS

Severity
7.8HIGHNVD
EPSS
1.1%
top 21.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 27
Latest updateMay 17

Description

Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.2 through 3.7 before 3.7.5S and 3.8 through 3.10 before 3.10.1S allow remote attackers to cause a denial of service (device reload) via a malformed IKEv2 packet, aka Bug ID CSCui88426.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages2 packages

NVDcisco/ios6 versions+5
NVDcisco/ios_xe61 versions+60

🔴Vulnerability Details

2
GHSA
GHSA-49q4-fhm6-hwc2: Cisco IOS 122022-05-17
CVEList
CVE-2014-2108: Cisco IOS 122014-03-27

💥Exploits & PoCs

1
Exploit-DB
Zenoss Monitoring System 4.2.5-2108 (x64) - Persistent Cross-Site Scripting2014-07-25

📋Vendor Advisories

2
CISA ICS
Rockwell Automation Stratix 59002017-05-10
Cisco
Cisco IOS Software Internet Key Exchange Version 2 Denial of Service Vulnerability2014-03-26
CVE-2014-2108 — Improper Input Validation in Cisco IOS | cvebase