CVE-2014-3293
published 2014-10-28CVE-2014-3293: Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet processing, which allows remote attackers to cause a denial of…
PriorityP427medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.74%
75.3th percentile
Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet processing, which allows remote attackers to cause a denial of service (BGP neighbor flapping) by sending many crafted IPv4 packets, aka Bug ID CSCuo29736.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ASR901 Crafted IPv4 Packet Denial of Service Vulnerability
vendor_cisco·2014-10-27·CVSS 5.0
CVE-2014-3293 [MEDIUM] CWE-20 Cisco ASR901 Crafted IPv4 Packet Denial of Service Vulnerability
Cisco ASR901 Crafted IPv4 Packet Denial of Service Vulnerability
A vulnerability in Internet Protocol version 4 (IPv4) packet processing of the Cisco ASR901 could allow an unauthenticated, remote attacker to flood packets to the ASR901 CPU.
The vulnerability is due to punting crafted IPv4 packets to the CPU for processing. An attacker could exploit this vulnerability by sending specifically crafted IPv4 packets. An exploit could allow the attacker to flood traffic to the CPU of the ASR901, which would result in BGP neighbor flaps.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send crafted packets to the targeted device. This access r
GHSA
GHSA-v734-5rx9-g3rm: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2014-3293 [MEDIUM] GHSA-v734-5rx9-g3rm: Cisco IOS 15
Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet processing, which allows remote attackers to cause a denial of service (BGP neighbor flapping) by sending many crafted IPv4 packets, aka Bug ID CSCuo29736.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/61830http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3293http://tools.cisco.com/security/center/viewAlert.x?alertId=36195http://www.securityfocus.com/bid/70744http://www.securitytracker.com/id/1031122https://exchange.xforce.ibmcloud.com/vulnerabilities/97769http://secunia.com/advisories/61830http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3293http://tools.cisco.com/security/center/viewAlert.x?alertId=36195http://www.securityfocus.com/bid/70744http://www.securitytracker.com/id/1031122https://exchange.xforce.ibmcloud.com/vulnerabilities/97769
2014-10-28
Published