CVE-2014-2124
published 2014-03-21CVE-2014-2124: Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 devices, allows remote attackers to cause a denial of…
PriorityP431high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.97%
78.3th percentile
Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 devices, allows remote attackers to cause a denial of service (device crash) via crafted multicast packets, aka Bug ID CSCuf60783.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.1\(2\)sy3 | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f77j-4prj-h765: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2014-2124 [HIGH] GHSA-f77j-4prj-h765: Cisco IOS 15
Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 devices, allows remote attackers to cause a denial of service (device crash) via crafted multicast packets, aka Bug ID CSCuf60783.
Cisco
Cisco IOS Software Sup2T Denial of Service Vulnerability
vendor_cisco·2014-03-19·CVSS 7.1
CVE-2014-2124 [HIGH] CWE-399 Cisco IOS Software Sup2T Denial of Service Vulnerability
Cisco IOS Software Sup2T Denial of Service Vulnerability
A vulnerability in Cisco Catalyst 6500 Supervisor Engine 2T (Sup2T) could allow an unauthenticated, remote attacker to crash the device.
The vulnerability is due to incorrect processing multicast traffic by the Sup2T. An attacker could exploit this vulnerability by sending crafted packets to the router to cause a denial of service (DoS) condition.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may need access to trusted, internal networks to send crafted packets to the targeted device. This access requirement decreases the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit code exists; however, t
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/57515http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2124http://tools.cisco.com/security/center/viewAlert.x?alertId=33413http://www.securityfocus.com/bid/66301http://www.securitytracker.com/id/1029942https://exchange.xforce.ibmcloud.com/vulnerabilities/91904http://secunia.com/advisories/57515http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2124http://tools.cisco.com/security/center/viewAlert.x?alertId=33413http://www.securityfocus.com/bid/66301http://www.securitytracker.com/id/1029942https://exchange.xforce.ibmcloud.com/vulnerabilities/91904
2014-03-21
Published