CVE-2014-3268Improper Input Validation in Cisco IOS

Severity
5.0MEDIUMNVD
EPSS
0.4%
top 38.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 20
Latest updateMay 17

Description

Cisco IOS 15.2(4)M4 on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service (input-queue consumption and traffic-processing outage) via crafted RTCP packets, aka Bug ID CSCuj72215.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDcisco/ios15.2\(4\)m4

🔴Vulnerability Details

2
GHSA
GHSA-6p5r-xqvf-22q2: Cisco IOS 152022-05-17
CVEList
CVE-2014-3268: Cisco IOS 152014-05-20

📋Vendor Advisories

1
Cisco
Cisco IOS Software RTCP Input Queue Vulnerability2014-05-19

💬Community

1
Bugzilla
CVE-2014-2856 cups: cross-site scripting flaw fixed in the 1.7.2 release2014-04-14
CVE-2014-3268 — Improper Input Validation in Cisco IOS | cvebase