CVE-2014-2109
published 2014-03-27CVE-2014-2109: The TCP Input module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (memory…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.24%
81.0th percentile
The TCP Input module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted TCP packets, aka Bug IDs CSCuh33843 and CSCuj41494.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
Cisco
Cisco IOS Software Network Address Translation Vulnerabilities
vendor_cisco·2014-03-26·CVSS 7.8
CVE-2014-2109 [HIGH] CWE-20 Cisco IOS Software Network Address Translation Vulnerabilities
Cisco IOS Software Network Address Translation Vulnerabilities
The Cisco IOS Software implementation of the Network Address Translation (NAT) feature contains two vulnerabilities when translating IP packets that could allow an unauthenticated, remote attacker to cause a denial of service condition.
Cisco has released software updates that address these vulnerabilities. There are no workarounds to mitigate these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140326-nat
Note: The March 26, 2014, Cisco IOS Software Security Advisory bundled publication includes six Cisco Security Advisories. All advisories address vulnerabilities in Cisco IOS Software. Each Cisco IOS Software Secur
Cisco
Cisco IOS Software Network Address Translation Vulnerabilities
vendor_cisco
CVE-2014-2109 Cisco IOS Software Network Address Translation Vulnerabilities
CVE-2014-2109: Cisco IOS Software Network Address Translation Vulnerabilities
The Cisco IOS Software implementation of the Network Address Translation (NAT) feature contains two vulnerabilities when translating IP packets that could allow an unauthenticated, remote attacker to cause a denial of service condition. Cisco has released software updates that address these vulnerabilities. There are no
CWE: CWE-20, CWE-399, CWE-20, CWE-399
Bug IDs: CSCue00996, CSCuh33843, CSCuj41494, CSCue00996, CSCuh33843
VulDB
Cisco IOS up to 15.4 DNS ALG input validation (cisco-sa-20140326-nat / Nessus ID 73345)
vuldb·2026-05-09·CVSS 7.8
CVE-2014-2109 [HIGH] Cisco IOS up to 15.4 DNS ALG input validation (cisco-sa-20140326-nat / Nessus ID 73345)
A vulnerability has been found in Cisco IOS up to 15.4 and classified as problematic. The impacted element is an unknown function of the component DNS ALG. The manipulation leads to improper input validation.
This vulnerability is documented as CVE-2014-2109. The attack can be initiated remotely. There is not any exploit available.
Applying a patch is the recommended action to fix this issue.
GHSA
GHSA-6p6v-7hf9-h7jf: The TCP Input module in Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2014-2109 [HIGH] CWE-20 GHSA-6p6v-7hf9-h7jf: The TCP Input module in Cisco IOS 12
The TCP Input module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted TCP packets, aka Bug IDs CSCuh33843 and CSCuj41494.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-03-27
Published