4.8
CVSSv2

CVE-2014-3295

Published: 14/06/2014 Updated: 08/09/2016
CVSS v2 Base Score: 4.8 | Impact Score: 4.9 | Exploitability Score: 6.5
VMScore: 427
Vector: AV:A/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The HSRP implementation in Cisco NX-OS 6.2(2a) and previous versions allows remote malicious users to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco nx-os 4.2.\\(2a\\)

cisco nx-os 4.2\\(4\\)

cisco nx-os 5.0\\(5\\)

cisco nx-os 5.1\\(1a\\)

cisco nx-os 5.2\\(7\\)

cisco nx-os 6.0\\(4\\)

cisco nx-os 6.0\\(2\\)

cisco nx-os

cisco nx-os 5.0\\(2a\\)

cisco nx-os 5.1\\(6\\)

cisco nx-os 5.1\\(5\\)

cisco nx-os 5.1\\(4\\)

cisco nx-os 6.1\\(4a\\)

cisco nx-os 6.1\\(4\\)

cisco nx-os 6.1\\(3\\)

cisco nx-os 6.1\\(2\\)

cisco nx-os 6.1\\(1\\)

cisco nx-os 4.1.\\(4\\)

cisco nx-os 4.1.\\(3\\)

cisco nx-os 4.1.\\(2\\)

cisco nx-os 4.2\\(8\\)

cisco nx-os 5.2\\(5\\)

cisco nx-os 5.2\\(4\\)

cisco nx-os 5.2\\(3a\\)

cisco nx-os 5.2\\(1\\)

cisco nx-os 4.1.\\(5\\)

cisco nx-os 4.2\\(6\\)

cisco nx-os 4.2\\(3\\)

cisco nx-os 5.0\\(3\\)

cisco nx-os 5.1\\(3\\)

cisco nx-os 5.2\\(9\\)

cisco nx-os 6.0\\(3\\)

cisco nx-os 6.0\\(1\\)

cisco nx-os 6.2\\(2\\)

Vendor Advisories

A vulnerability in Hot Standby Router Protocol (HSRP) authentication in the Cisco Nexus series could allow an unauthenticated, adjacent attacker to affect the state of HSRP group members and cause black holing of traffic The vulnerability is due to incorrect parsing of malformed HSRP packets An attacker could exploit this vulnerability by sendin ...