CVE-2014-2113
published 2014-03-27CVE-2014-2113: Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.99%
78.5th percentile
Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CSCui59540.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
Cisco
Cisco IOS Software Crafted IPv6 Packet Denial of Service Vulnerability
vendor_cisco·2014-03-26·CVSS 7.8
CVE-2014-2113 [HIGH] CWE-20 Cisco IOS Software Crafted IPv6 Packet Denial of Service Vulnerability
Cisco IOS Software Crafted IPv6 Packet Denial of Service Vulnerability
A vulnerability in the implementation of the IP version 6 (IPv6) protocol stack in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause I/O memory depletion on an affected device that has IPv6 enabled. The vulnerability is triggered when an affected device processes a malformed IPv6 packet.
Cisco has released software updates that address this vulnerability. There are no workarounds to mitigate this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140326-ipv6
Note: The March 26, 2014, Cisco IOS Software Security Advisory bundled publication includes six Cisco Secur
Cisco
Cisco IOS Software Crafted IPv6 Packet Denial of Service Vulnerability
vendor_cisco
CVE-2014-2113 Cisco IOS Software Crafted IPv6 Packet Denial of Service Vulnerability
CVE-2014-2113: Cisco IOS Software Crafted IPv6 Packet Denial of Service Vulnerability
A vulnerability in the implementation of the IP version 6 (IPv6) protocol stack in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause I/O memory depletion on an affected device that has IPv6 enabled. The vulnerability is triggered when an affected device processes a malformed IPv6 packet. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-20, CWE-20
Bug IDs: CSCui59540, CSCui59540
VulDB
Cisco IOS IPv6 Stack input validation (cisco-sa-20140326-ipv6 / Nessus ID 73343)
vuldb·2026-05-09·CVSS 7.8
CVE-2014-2113 [HIGH] Cisco IOS IPv6 Stack input validation (cisco-sa-20140326-ipv6 / Nessus ID 73343)
A vulnerability was found in Cisco IOS. It has been declared as problematic. Affected is an unknown function of the component IPv6 Stack. Such manipulation leads to improper input validation.
This vulnerability is traded as CVE-2014-2113. The attack may be launched remotely. There is no exploit available.
Applying a patch is advised to resolve this issue.
GHSA
GHSA-2xwj-cxrx-46h4: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2014-2113 [HIGH] CWE-20 GHSA-2xwj-cxrx-46h4: Cisco IOS 15
Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CSCui59540.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-03-27
Published