PT-2014-5239 · Cisco · Cisco 1800 Series Integrated Services Routers+1

Published

2014-08-28

·

Updated

2017-08-29

·

CVE-2014-3347

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco 1800 Series Integrated Services Routers (ISR) version 15.1(4)M2
Description The issue allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid state of the hardware encryption module. This occurs when the ISDN Basic Rate Interface is enabled. An attacker would need to perform the attack exactly when the device polls the hardware encryption module to perform entropy collection. To exploit this vulnerability, an attacker must obtain additional knowledge of the targeted device, such as whether ISDN BRI is configured and connected to an active switched network and whether a service that requires encryption entropy collection is enabled.
Recommendations For Cisco 1800 Series Integrated Services Routers (ISR) version 15.1(4)M2, consider disabling the ISDN Basic Rate Interface (BRI) to minimize the risk of exploitation, as fixed software will not be released due to the device having reached the End of Software Maintenance milestone.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3347

Affected Products

Cisco 1800 Series Integrated Services Routers
Cisco Ios