CVE-2014-3409
published 2014-10-25CVE-2014-3409: The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and earlier and IOS XE 3.13S and earlier allows remote attackers…
PriorityP423medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
1.01%
58.9th percentile
The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and earlier and IOS XE 3.13S and earlier allows remote attackers to cause a denial of service (device reload) via malformed CFM packets, aka Bug ID CSCuq93406.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 12.2\(33\)sre9a | — |
| cisco | ios_xe | <= 3.13s | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/61799http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3409http://tools.cisco.com/security/center/viewAlert.x?alertId=36184http://www.securityfocus.com/bid/70715http://www.securitytracker.com/id/1031119https://exchange.xforce.ibmcloud.com/vulnerabilities/97758http://secunia.com/advisories/61799http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3409http://tools.cisco.com/security/center/viewAlert.x?alertId=36184http://www.securityfocus.com/bid/70715http://www.securitytracker.com/id/1031119https://exchange.xforce.ibmcloud.com/vulnerabilities/97758
2014-10-25
Published