PT-2014-5169 · Cisco · Cisco Switches+1
Published
2014-05-20
·
Updated
2016-09-07
·
CVE-2014-3273
CVSS v2.0
6.1
Medium
| Vector | AV:A/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS (affected versions not specified)
Cisco switches (affected versions not specified)
Description
The issue is related to the Link Layer Discovery Protocol (LLDP) implementation, which allows remote attackers to cause a denial of service (device reload) via a malformed packet. This is due to incorrect handling of malformed LLDP packets. An attacker could exploit this by sending a malformed LLDP packet to a switch when LLDP is enabled. The attacker needs access to the same collision or broadcast domain as the targeted device to send the packets.
Recommendations
For Cisco IOS, update to a version that includes the fix for Bug ID CSCum96282.
For Cisco switches, apply the software updates released by Cisco to address the vulnerability in Link Layer Discovery Protocol (LLDP).
As a temporary workaround, consider disabling LLDP on affected devices until a patch is available.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios
Cisco Switches