5
CVSSv2

CVE-2014-3330

Published: 11/08/2014 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote malicious users to bypass intended access restrictions via a flood of packets matching a policy that contains the log keyword, aka Bug ID CSCuo02489.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco nx-os 6.1\\(2\\)i2\\(1\\)

cisco nexus_9000 -

Vendor Advisories

A vulnerability in the implementation of the access list logging feature of Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to bypass the access list restriction for the logged traffic The vulnerability is due to insufficient policy checks for the logged packets An attacker could exploit this vulnerability by sen ...