PT-2014-5158 · Cisco · Cisco Ios+1

Published

2014-05-14

·

Updated

2016-09-07

·

CVE-2014-3262

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 15.3(3)S and earlier Cisco IOS XE (affected versions not specified)
Description The Locator/ID Separation Protocol (LISP) implementation does not properly validate parameters in ITR control messages, allowing remote attackers to cause a denial of service via malformed messages. This vulnerability is due to insufficient checking of certain parameters in LISP control messages on the Ingress Tunnel Router (ITR). An attacker could exploit this vulnerability by sending malformed LISP control messages to the ITR, causing a vulnerable device to disable Cisco Express Forwarding and eventually drop traffic passing through. To exploit this vulnerability, an attacker may need access to trusted, internal networks to send malformed LISP control messages to a targeted device.
Recommendations For Cisco IOS versions 15.3(3)S and earlier, update to a fixed software version. For Cisco IOS XE, update to a fixed software version. As a temporary workaround, consider restricting access to the Ingress Tunnel Router (ITR) to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3262

Affected Products

Cisco Ios
Cisco Ios Xe