CVE-2014-3335
published 2014-08-26CVE-2014-3335: Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which…
PriorityP421medium4.6CVSS 2.0
AVAACHAuNCNINAC
EPSS
1.11%
62.5th percentile
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of service (chip and card hangs) via a crafted packet, aka Bug ID CSCup77750.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | <= 4.3.2 | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| linux | linux_kernel | >= 0 < 3.13.0-123.172 | 3.13.0-123.172 |
CVSS provenance
nvdv2.04.6MEDIUMAV:A/AC:H/Au:N/C:N/I:N/A:C
osv7.0HIGH
vendor_cisco4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5cw5-jwpw-v565: Cisco IOS XR 4
ghsa_unreviewed·2022-05-17
CVE-2014-3335 [MEDIUM] CWE-20 GHSA-5cw5-jwpw-v565: Cisco IOS XR 4
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of service (chip and card hangs) via a crafted packet, aka Bug ID CSCup77750.
OSV
linux vulnerabilities
osv·2017-06-29·CVSS 7.0
CVE-2014-9940 linux vulnerabilities
linux vulnerabilities
USN 3335-1 fixed a vulnerability in the Linux kernel. However, that
fix introduced regressions for some Java applications. This update
addresses the issue. We apologize for the inconvenience.
It was discovered that a use-after-free vulnerability in the core voltage
regulator driver of the Linux kernel. A local attacker could use this to
cause a denial of service or possibly execute arbitrary code.
(CVE-2014-9940)
It was discovered that a buffer overflow existed in the trace subsystem in
the Linux kernel. A privileged local attacker could use this to execute
arbitrary code. (CVE-2017-0605)
Roee Hay discovered that the parallel port printer driver in the Linux
kernel did not properly bounds check passed arguments. A local attacker
with write access to the kernel com
Cisco
Cisco IOS XR Software Packet Parsing Denial of Service Vulnerability
vendor_cisco·2014-08-25·CVSS 4.6
CVE-2014-3335 [MEDIUM] CWE-399 Cisco IOS XR Software Packet Parsing Denial of Service Vulnerability
Cisco IOS XR Software Packet Parsing Denial of Service Vulnerability
A vulnerability in the packet parsing code of Cisco IOS XR Software for ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause a lockup and eventual reload of a Network Processor (NP) chip and a line card processing traffic.
The vulnerability is due to improper parsing of a specific packet when NetFlow sampling is configured. An attacker could exploit this vulnerability by sending a specific packet with a multicast destination MAC address through an affected device that has NetFlow sampling configured. An exploit could allow the attacker to cause a lockup and eventual reload of an NP chip and a line card processing traffic.
Cisco has confirmed the vulnerability in a secu
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/60222http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3335http://tools.cisco.com/security/center/viewAlert.x?alertId=35416http://www.securityfocus.com/bid/69383http://www.securitytracker.com/id/1030757https://exchange.xforce.ibmcloud.com/vulnerabilities/95443http://secunia.com/advisories/60222http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3335http://tools.cisco.com/security/center/viewAlert.x?alertId=35416http://www.securityfocus.com/bid/69383http://www.securitytracker.com/id/1030757https://exchange.xforce.ibmcloud.com/vulnerabilities/95443
2014-08-26
Published