7.8
CVSSv2

CVE-2014-3355

Published: 25/09/2014 Updated: 29/08/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The metadata flow feature in Cisco IOS 15.1 up to and including 15.3 and IOS XE 3.3.xXO prior to 3.3.1XO, 3.6.xS and 3.7.xS prior to 3.7.6S, and 3.8.xS, 3.9.xS, and 3.10.xS prior to 3.10.1S allows remote malicious users to cause a denial of service (device reload) via malformed RSVP packets, aka Bug ID CSCug75942.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe 3.7\\(2\\)s

cisco ios xe 3.7\\(3\\)s

cisco ios xe 3.9\\(1a\\)s

cisco ios xe 3.9\\(2\\)s

cisco ios xe 3.6.1s

cisco ios xe 3.6.2s

cisco ios xe 3.8\\(0\\)s

cisco ios xe 3.8\\(1\\)s

cisco ios xe 3.3\\(.0\\)xo

cisco ios xe 3.6.0s

cisco ios xe 3.7\\(4\\)s

cisco ios xe 3.7\\(5\\)s

cisco ios xe 3.10s

cisco ios xe 3.7\\(1\\)as

cisco ios xe 3.7\\(0\\)s

cisco ios xe 3.8\\(2\\)s

cisco ios xe 3.9\\(0\\)s

Vendor Advisories

Two vulnerabilities in the metadata flow feature of Cisco IOS Software could allow an unauthenticated, remote attacker to reload a vulnerable device The vulnerabilities are due to improper handling of transit RSVP packets that need to be processed by the metadata infrastructure An attacker could exploit these vulnerabilities by sending malformed ...