5
CVSSv2

CVE-2014-2143

Published: 04/04/2014 Updated: 04/04/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The IKE implementation in Cisco IOS 15.4(1)T and previous versions and IOS XE allows remote malicious users to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 15.3s

cisco ios 15.4

cisco ios xe -

cisco ios

cisco ios 15.0\\(1\\)se

cisco ios 15.3\\(3\\)m

cisco ios 15.3\\(3\\)m2

cisco ios 15.1

cisco ios 15.2

cisco ios 15.3

cisco ios 15.3\\(2\\)s

cisco ios 15.0

cisco ios 15.3\\(3\\)m1

cisco ios 15.3\\(3\\)s

Vendor Advisories

A vulnerability in the Internet Key Exchange (IKE) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to delete established security associations on an affected device The vulnerability is due to improper handling of rogue IKE Main Mode packets An attacker could exploit this vulnerability by se ...