CVE-2014-3262
published 2014-05-16CVE-2014-3262: The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.55%
72.2th percentile
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of service (CEF outage and packet drops) via malformed messages, aka Bug ID CSCun73782.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.3\(3\)s | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software and IOS XE Software LISP Denial of Service Vulnerability
vendor_cisco·2014-05-14·CVSS 4.3
CVE-2014-3262 [MEDIUM] CWE-20 Cisco IOS Software and IOS XE Software LISP Denial of Service Vulnerability
Cisco IOS Software and IOS XE Software LISP Denial of Service Vulnerability
A vulnerability in Locator/ID Separation Protocol (LISP) control message processing in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a vulnerable device to disable Cisco Express Forwarding and eventually drop traffic passing through.
The vulnerability is due to insufficient checking of certain parameters in LISP control messages on the Ingress Tunnel Router (ITR). An attacker could exploit this vulnerability by sending malformed LISP control messages to the ITR. An exploit could allow the attacker to cause a vulnerable device to disable Cisco Express Forwarding and eventually drop traffic passing through.
Cisco has confirmed the vulnerability in a security
GHSA
GHSA-mf7q-r36h-f2c2: The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2014-3262 [MEDIUM] CWE-20 GHSA-mf7q-r36h-f2c2: The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of service (CEF outage and packet drops) via malformed messages, aka Bug ID CSCun73782.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3262http://tools.cisco.com/security/center/viewAlert.x?alertId=34233http://www.securitytracker.com/id/1030243http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3262http://tools.cisco.com/security/center/viewAlert.x?alertId=34233http://www.securitytracker.com/id/1030243
2014-05-16
Published