CVE-2014-3360OS Command Injection in Cisco IOS

Severity
7.8HIGHNVD
EPSS
1.9%
top 16.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 25
Latest updateMay 17

Description

Cisco IOS 12.4 and 15.0 through 15.4 and IOS XE 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S; and 3.11.xS before 3.12S allow remote attackers to cause a denial of service (device reload) via a crafted SIP message, aka Bug ID CSCul46586.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages2 packages

NVDcisco/ios4 versions+3
NVDcisco/ios_xe42 versions+41

🔴Vulnerability Details

2
GHSA
GHSA-624c-r277-x6jw: Cisco IOS 122022-05-17
CVEList
CVE-2014-3360: Cisco IOS 122014-09-25

📋Vendor Advisories

2
CISA ICS
Rockwell Automation Stratix 59002017-05-10
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability2014-09-24

💬Community

1
Bugzilla
CVE-2014-3859 bind: assertion failure during EDNS option processing2014-06-12
CVE-2014-3360 — OS Command Injection in Cisco IOS | cvebase