PT-2014-5167 · Cisco · Cisco Ios Xr

Published

2014-05-20

·

Updated

2016-09-07

·

CVE-2014-3271

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Cisco IOS XR (affected versions not specified)
Description The issue is related to the DHCPv6 implementation, which allows remote attackers to cause a denial of service by sending a malformed packet. This is due to incorrect handling of such packets. An attacker could exploit this by sending a malformed DHCPv6 packet to a device configured with DHCPv6 server functionality, potentially causing the DHCPv6 process to crash. The attack may require access to internal networks and the device must be configured with DHCPv6 server functionality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3271

Affected Products

Cisco Ios Xr