CVE-2014-3321
published 2014-07-18CVE-2014-3321: Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of…
PriorityP424medium5.7CVSS 2.0
AVAACMAuNCNINAC
EPSS
0.65%
47.4th percentile
Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | <= 4.3.4 | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.05.7MEDIUMAV:A/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XR Software MPLS Packet Denial of Service Vulnerability
vendor_cisco·2014-07-15·CVSS 5.7
CVE-2014-3321 [MEDIUM] CWE-20 Cisco IOS XR Software MPLS Packet Denial of Service Vulnerability
Cisco IOS XR Software MPLS Packet Denial of Service Vulnerability
A vulnerability in parsing crafted Multiprotocol Label Switching (MPLS) packets in Cisco IOS XR Software for ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause a lockup and eventual reload of a network processor chip and a line card processing traffic.
The vulnerability is due to insufficient logic in parsing MPLS packets. An attacker could exploit this vulnerability by sending a stream of crafted MPLS packets to be routed by a bridge-group virtual interface (BVI) on the affected device. An exploit could allow the attacker to cause a lockup and eventual reload of a network processor chip and a line card, leading to a denial of service (DoS) condition.
Cisco has confirme
GHSA
GHSA-w963-wfhc-pqh3: Cisco IOS XR 4
ghsa_unreviewed·2022-05-17
CVE-2014-3321 [MEDIUM] CWE-20 GHSA-w963-wfhc-pqh3: Cisco IOS XR 4
Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3321http://tools.cisco.com/security/center/viewAlert.x?alertId=34936http://www.securitytracker.com/id/1030597http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3321http://tools.cisco.com/security/center/viewAlert.x?alertId=34936http://www.securitytracker.com/id/1030597
2014-07-18
Published