PT-2014-5158 · Cisco · Cisco Ios+1
Published
2014-05-14
·
Updated
2016-09-07
·
CVE-2014-3262
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 15.3(3)S and earlier
Cisco IOS XE (affected versions not specified)
Description
The Locator/ID Separation Protocol (LISP) implementation does not properly validate parameters in ITR control messages, allowing remote attackers to cause a denial of service via malformed messages. This vulnerability is due to insufficient checking of certain parameters in LISP control messages on the Ingress Tunnel Router (ITR). An attacker could exploit this vulnerability by sending malformed LISP control messages to the ITR, causing a vulnerable device to disable Cisco Express Forwarding and eventually drop traffic passing through. To exploit this vulnerability, an attacker may need access to trusted, internal networks to send malformed LISP control messages to a targeted device.
Recommendations
For Cisco IOS versions 15.3(3)S and earlier, update to a fixed software version.
For Cisco IOS XE, update to a fixed software version.
As a temporary workaround, consider restricting access to the Ingress Tunnel Router (ITR) to minimize the risk of exploitation.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios
Cisco Ios Xe