7.8
CVSSv2

CVE-2014-2109

Published: 27/03/2014 Updated: 23/05/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The TCP Input module in Cisco IOS 12.2 up to and including 12.4 and 15.0 up to and including 15.4, when NAT is used, allows remote malicious users to cause a denial of service (memory consumption or device reload) via crafted TCP packets, aka Bug IDs CSCuh33843 and CSCuj41494.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 15.4

cisco ios 15.3

cisco ios 12.2

cisco ios 15.2

cisco ios 15.1

cisco ios 15.0

cisco ios 12.4

cisco ios 12.3

Vendor Advisories

The Cisco IOS Software implementation of the Network Address Translation (NAT) feature contains two vulnerabilities when translating IP packets that could allow an unauthenticated, remote attacker to cause a denial of service condition Cisco has released software updates that address these vulnerabilities There are no workarounds to mitigate the ...