CVE-2014-3295
published 2014-06-14CVE-2014-3295: The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state…
PriorityP423medium4.8CVSS 2.0
AVAACLAuNCNIPAP
EPSS
1.12%
62.7th percentile
The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | <= 6.2\(2a\) | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.04.8MEDIUMAV:A/AC:L/Au:N/C:N/I:P/A:P
vendor_cisco4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco NX-OS Software HSRP Authentication Denial of Service Vulnerability
vendor_cisco·2014-06-11·CVSS 4.8
CVE-2014-3295 [MEDIUM] CWE-287 Cisco NX-OS Software HSRP Authentication Denial of Service Vulnerability
Cisco NX-OS Software HSRP Authentication Denial of Service Vulnerability
A vulnerability in Hot Standby Router Protocol (HSRP) authentication in the Cisco Nexus series could allow an unauthenticated, adjacent attacker to affect the state of HSRP group members and cause black holing of traffic.
The vulnerability is due to incorrect parsing of malformed HSRP packets. An attacker could exploit this vulnerability by sending malformed HSRP packets to bypass HSRP authentication. An exploit could allow the attacker to bypass HSRP authentication and affect the state of active HSRP group members, causing them to go to SPEAK state, which leads to black holing of traffic and causes a denial of service (DoS) condition.
Cisco has confirmed the vulnerability in a security notice; however, software up
GHSA
GHSA-6qgq-2pg7-h3gh: The HSRP implementation in Cisco NX-OS 6
ghsa_unreviewed·2022-05-17
CVE-2014-3295 [MEDIUM] CWE-287 GHSA-6qgq-2pg7-h3gh: The HSRP implementation in Cisco NX-OS 6
The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/59158http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3295http://tools.cisco.com/security/center/viewAlert.x?alertId=34585http://www.securityfocus.com/bid/67983http://www.securitytracker.com/id/1030409http://secunia.com/advisories/59158http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3295http://tools.cisco.com/security/center/viewAlert.x?alertId=34585http://www.securityfocus.com/bid/67983http://www.securitytracker.com/id/1030409
2014-06-14
Published