4.8
CVSSv2

CVE-2014-3295

Published: 14/06/2014 Updated: 08/09/2016
CVSS v2 Base Score: 4.8 | Impact Score: 4.9 | Exploitability Score: 6.5
VMScore: 427
Vector: AV:A/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The HSRP implementation in Cisco NX-OS 6.2(2a) and previous versions allows remote malicious users to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.

Affected Products

Vendor Product Versions
CiscoNx-os4.1.(2), 4.1.(3), 4.1.(4), 4.1.(5), 4.2(3), 4.2(4), 4.2(6), 4.2(8), 4.2.(2a), 5.0(2a), 5.0(3), 5.0(5), 5.1(1a), 5.1(3), 5.1(4), 5.1(5), 5.1(6), 5.2(1), 5.2(3a), 5.2(4), 5.2(5), 5.2(7), 5.2(9), 6.0(1), 6.0(2), 6.0(3), 6.0(4), 6.1(1), 6.1(2), 6.1(3), 6.1(4), 6.1(4a), 6.2(2), 6.2(2a)

Vendor Advisories

A vulnerability in Hot Standby Router Protocol (HSRP) authentication in the Cisco Nexus series could allow an unauthenticated, adjacent attacker to affect the state of HSRP group members and cause black holing of traffic The vulnerability is due to incorrect parsing of malformed HSRP packets An attacker could exploit this vulnerability by sendin ...