7.8
CVSSv2

CVE-2014-3359

Published: 25/09/2014 Updated: 29/08/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Memory leak in Cisco IOS 15.1 up to and including 15.4 and IOS XE 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS prior to 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS prior to 3.10.1S; and 3.11.xS prior to 3.12S allows remote malicious users to cause a denial of service (memory consumption or device reload) via malformed DHCPv6 packets, aka Bug ID CSCum90081.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 15.4

cisco ios xe 3.4.0s

cisco ios xe 3.5.2s

cisco ios xe 3.6s\\(.0\\)

cisco ios xe 3.7\\(4\\)s

cisco ios xe 3.7\\(5\\)s

cisco ios xe 3.9s\\(.2\\)

cisco ios xe 3.10

cisco ios xe 3.10.0s

cisco ios 15.1

cisco ios xe 3.4.4s

cisco ios xe 3.4.5s

cisco ios xe 3.7\\(0\\)s

cisco ios xe 3.7\\(1\\)as

cisco ios xe 3.8s\\(.1\\)

cisco ios xe 3.8s\\(.2\\)

cisco ios xe 3.11.2s

cisco ios xe 3.4.1s

cisco ios xe 3.4.2s

cisco ios xe 3.4.3s

cisco ios xe 3.6s\\(.1\\)

cisco ios xe 3.6s\\(.2\\)

cisco ios xe 3.8.0s

cisco ios xe 3.8s\\(.0\\)

cisco ios xe 3.11.0s

cisco ios xe 3.11.1s

cisco ios 15.2

cisco ios 15.3

cisco ios xe 3.5.0s

cisco ios xe 3.5.1s

cisco ios xe 3.7\\(2\\)s

cisco ios xe 3.7\\(3\\)s

cisco ios xe 3.9s\\(.0\\)

cisco ios xe 3.9s\\(.1\\)

Vendor Advisories

A vulnerability in the DHCP version 6 (DHCPv6) server implementation of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition The vulnerability is due to improper parsing of malformed DHCPv6 packets An attacker could exploit this vulnerability by sending malforme ...