PT-2014-5298 · Cisco · Cisco Ios+1
Published
2014-10-25
·
Updated
2017-08-29
·
CVE-2014-3409
CVSS v2.0
6.1
Medium
| Vector | AV:A/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions prior to 12.2(33)SRE9a
Cisco IOS XE versions prior to 3.13S
Description
The issue affects the Ethernet Connectivity Fault Management handling feature, allowing remote attackers to cause a denial of service by sending malformed CFM packets, which can lead to a device reload.
Recommendations
For Cisco IOS versions prior to 12.2(33)SRE9a, update to a version later than 12.2(33)SRE9a to resolve the issue.
For Cisco IOS XE versions prior to 3.13S, update to a version later than 3.13S to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios
Cisco Ios Xe