CVE-2014-2183
published 2014-04-29CVE-2014-2183: The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via…
PriorityP427medium6.3CVSS 2.0
AVNACMAuSCNINAC
EPSS
1.32%
67.9th percentile
The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP packet, aka Bug ID CSCun09973.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xe | <= 3.10.2s | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv2.06.3MEDIUMAV:N/AC:M/Au:S/C:N/I:N/A:C
vendor_cisco6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Software Malformed L2TP Packet Vulnerability
vendor_cisco·2014-04-28·CVSS 6.3
CVE-2014-2183 [MEDIUM] CWE-399 Cisco IOS XE Software Malformed L2TP Packet Vulnerability
Cisco IOS XE Software Malformed L2TP Packet Vulnerability
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) module of Cisco IOS XE on Cisco ASR 1000 Series Routers could allow an authenticated, remote attacker to cause a reload of the processing ESP card.
The vulnerability occurs during the processing of a malformed L2TP packet. An attacker could exploit this vulnerability by sending malformed L2TP packets over an established L2TP session. An exploit could allow the attacker to cause a reload of the affected ESP card.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker must authenticate to a targeted device. This access requirement decreases the likelihood of a successful exploit attempt.
Cisco in
GHSA
GHSA-g543-f6ff-6mj2: The L2TP module in Cisco IOS XE 3
ghsa_unreviewed·2022-05-13
CVE-2014-2183 [MEDIUM] CWE-20 GHSA-g543-f6ff-6mj2: The L2TP module in Cisco IOS XE 3
The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP packet, aka Bug ID CSCun09973.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-04-29
Published