CVE-2014-3268
published 2014-05-20CVE-2014-3268: Cisco IOS 15.2(4)M4 on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service (input-queue consumption and…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.22%
65.1th percentile
Cisco IOS 15.2(4)M4 on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service (input-queue consumption and traffic-processing outage) via crafted RTCP packets, aka Bug ID CSCuj72215.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software RTCP Input Queue Vulnerability
vendor_cisco·2014-05-19·CVSS 5.0
CVE-2014-3268 [MEDIUM] CWE-399 Cisco IOS Software RTCP Input Queue Vulnerability
Cisco IOS Software RTCP Input Queue Vulnerability
A vulnerability in handling Real-Time Control Protocol (RTCP) traffic in Cisco Unified Border Element (CUBE) could allow an unauthenticated, remote attacker to cause traffic that is destined to an affected device and traffic that needs to be processed switched to fail.
The vulnerability is due to exhaustion of the interface input queue by the RTCP traffic. An attacker could exploit this vulnerability by sending RTCP packets in a specific sequence. An exploit could allow the attacker to cause traffic to fail that is destined to an affected device as well as traffic that needs to be processed switched.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may
GHSA
GHSA-6p5r-xqvf-22q2: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2014-3268 [MEDIUM] CWE-20 GHSA-6p5r-xqvf-22q2: Cisco IOS 15
Cisco IOS 15.2(4)M4 on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service (input-queue consumption and traffic-processing outage) via crafted RTCP packets, aka Bug ID CSCuj72215.
No detection rules found.
No public exploits indexed.
2014-05-20
Published