7.8
CVSSv2

CVE-2014-2108

Published: 27/03/2014 Updated: 28/03/2014
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco IOS 12.2 and 15.0 up to and including 15.3 and IOS XE 3.2 up to and including 3.7 prior to 3.7.5S and 3.8 up to and including 3.10 prior to 3.10.1S allow remote malicious users to cause a denial of service (device reload) via a malformed IKEv2 packet, aka Bug ID CSCui88426.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 12.2

cisco ios 15.3

cisco ios 15.2

cisco ios 15.1

cisco ios 15.0

cisco ios 15.0\\(1\\)se

cisco ios xe 3.9.0s

cisco ios xe 3.9.1s

cisco ios xe 3.8.0s

cisco ios xe 3.8s\\(.0\\)

cisco ios xe 3.8s\\(.1\\)

cisco ios xe 3.5.0s

cisco ios xe 3.5.1s

cisco ios xe 3.5.2s

cisco ios xe 3.5.xs

cisco ios xe 3.4s\\(.2\\)

cisco ios xe 3.4s\\(.3\\)

cisco ios xe 3.4s\\(.4\\)

cisco ios xe 3.4s\\(.5\\)

cisco ios xe 3.2.4sg

cisco ios xe 3.2.3sg

cisco ios xe 3.2.2sg

cisco ios xe 3.2.2s

cisco ios xe 3.10

cisco ios xe 3.7.0s

cisco ios xe 3.7.2s

cisco ios xe 3.6.2s

cisco ios xe 3.6s\\(.1\\)

cisco ios xe 3.5s\\(.1\\)

cisco ios xe 3.4.0as

cisco ios xe 3.4.xs

cisco ios xe 3.4s\\(.1\\)

cisco ios xe 3.4s\\(.6\\)

cisco ios xe 3.3.0sg

cisco ios xe 3.3s\\(.2\\)

cisco ios xe 3.2s\\(.1\\)

cisco ios xe 3.2.1s

cisco ios xe 3.2.0sg

cisco ios xe 3.7s\\(.0\\)

cisco ios xe 3.7s\\(.1\\)

cisco ios xe 3.6.0s

cisco ios xe 3.6.1s

cisco ios xe 3.4.0s

cisco ios xe 3.4.1s

cisco ios xe 3.4.2s

cisco ios xe 3.4.3s

cisco ios xe 3.4.4s

cisco ios xe 3.3.1sg

cisco ios xe 3.3.2s

cisco ios xe 3.3.3s

cisco ios xe 3.3s\\(.0\\)

cisco ios xe 3.2.0s

cisco ios xe 3.8s\\(.2\\)

cisco ios xe 3.7.1s

cisco ios xe 3.6s\\(.0\\)

cisco ios xe 3.6s\\(.2\\)

cisco ios xe 3.5s\\(.0\\)

cisco ios xe 3.5s\\(.2\\)

cisco ios xe 3.4.5s

cisco ios xe 3.4s\\(.0\\)

cisco ios xe 3.3.0s

cisco ios xe 3.3.1s

cisco ios xe 3.3s\\(.1\\)

cisco ios xe 3.2s\\(.2\\)

cisco ios xe 3.2s\\(.0\\)

cisco ios xe 3.2.1sg

cisco ios xe 3.2.0xo

Vendor Advisories

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of the affected device that would lead to a denial of service (DoS) condition The vulnerability is due to how an affected device processes certain malformed IKEv2 p ...