PT-2014-5169 · Cisco · Cisco Switches+1

Published

2014-05-20

·

Updated

2016-09-07

·

CVE-2014-3273

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS (affected versions not specified) Cisco switches (affected versions not specified)
Description The issue is related to the Link Layer Discovery Protocol (LLDP) implementation, which allows remote attackers to cause a denial of service (device reload) via a malformed packet. This is due to incorrect handling of malformed LLDP packets. An attacker could exploit this by sending a malformed LLDP packet to a switch when LLDP is enabled. The attacker needs access to the same collision or broadcast domain as the targeted device to send the packets.
Recommendations For Cisco IOS, update to a version that includes the fix for Bug ID CSCum96282. For Cisco switches, apply the software updates released by Cisco to address the vulnerability in Link Layer Discovery Protocol (LLDP). As a temporary workaround, consider disabling LLDP on affected devices until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3273

Affected Products

Cisco Ios
Cisco Switches