CVE-2014-2143
published 2014-04-04CVE-2014-2143: The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.75%
75.1th percentile
The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.4\(1\)t | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software and Cisco IOS XE Software IKE Main Mode Vulnerability
vendor_cisco·2014-04-03·CVSS 5.0
CVE-2014-2143 [MEDIUM] CWE-399 Cisco IOS Software and Cisco IOS XE Software IKE Main Mode Vulnerability
Cisco IOS Software and Cisco IOS XE Software IKE Main Mode Vulnerability
A vulnerability in the Internet Key Exchange (IKE) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to delete established security associations on an affected device.
The vulnerability is due to improper handling of rogue IKE Main Mode packets. An attacker could exploit this vulnerability by sending a crafted IKE Main Mode packet to an affected device. An exploit could allow the attacker to cause valid, established IKE security associations on an affected device to drop.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may need access to trusted, internal networks to send craft
GHSA
GHSA-9q73-pqxf-h52m: The IKE implementation in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2014-2143 [MEDIUM] GHSA-9q73-pqxf-h52m: The IKE implementation in Cisco IOS 15
The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021.
No detection rules found.
No writeups or analysis indexed.
2014-04-04
Published