PT-2014-5169 · Cisco · Cisco Switches+1

Publicado

2014-05-20

·

Atualizado

2016-09-07

·

CVE-2014-3273

CVSS v2.0

6.1

Média

VetorAV:A/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS (affected versions not specified) Cisco switches (affected versions not specified)
Description The issue is related to the Link Layer Discovery Protocol (LLDP) implementation, which allows remote attackers to cause a denial of service (device reload) via a malformed packet. This is due to incorrect handling of malformed LLDP packets. An attacker could exploit this by sending a malformed LLDP packet to a switch when LLDP is enabled. The attacker needs access to the same collision or broadcast domain as the targeted device to send the packets.
Recommendations For Cisco IOS, update to a version that includes the fix for Bug ID CSCum96282. For Cisco switches, apply the software updates released by Cisco to address the vulnerability in Link Layer Discovery Protocol (LLDP). As a temporary workaround, consider disabling LLDP on affected devices until a patch is available.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3273

Produtos afetados

Cisco Ios
Cisco Switches