CVE-2014-8005
published 2014-11-26CVE-2014-8005: Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.19%
64.7th percentile
Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | <= 5.1.0 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9446-w3xx-qr8h: Race condition in the lighttpd module in Cisco IOS XR 5
ghsa_unreviewed·2022-05-17
CVE-2014-8005 [MEDIUM] CWE-362 GHSA-9446-w3xx-qr8h: Race condition in the lighttpd module in Cisco IOS XR 5
Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.
Cisco
Cisco IOS XR Software lighttpd TCP Session Vulnerability
vendor_cisco·2014-11-25·CVSS 5.0
CVE-2014-8005 [MEDIUM] CWE-362 Cisco IOS XR Software lighttpd TCP Session Vulnerability
Cisco IOS XR Software lighttpd TCP Session Vulnerability
A vulnerability in the lighttpd module of Cisco IOS XR could allow an unauthenticated, remote attacker to cause a reload of the affected lighttpd process.
The vulnerability is due to a race condition while handling TCP sessions to the lighttpd module on the affected Cisco IOS XR device. An attacker could exploit this vulnerability by sending a number of TCP sessions to be established with the lighttpd server on the affected device. An exploit could allow the attacker to cause a reload of the lighttpd process.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send numerous TCP sessi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8005http://tools.cisco.com/security/center/viewAlert.x?alertId=36532http://www.securityfocus.com/bid/71287http://www.securitytracker.com/id/1031262https://exchange.xforce.ibmcloud.com/vulnerabilities/98937http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8005http://tools.cisco.com/security/center/viewAlert.x?alertId=36532http://www.securityfocus.com/bid/71287http://www.securitytracker.com/id/1031262https://exchange.xforce.ibmcloud.com/vulnerabilities/98937
2014-11-26
Published