5
CVSSv2

CVE-2014-3378

Published: 20/09/2014 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

tacacsd in Cisco IOS XR 5.1 and previous versions allows remote malicious users to cause a denial of service (process reload) via a malformed TACACS+ packet, aka Bug ID CSCum00468.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xr 4.2.0

cisco ios xr 4.1.2

cisco ios xr 4.0.0

cisco ios xr 3.9.2

cisco ios xr 3.8.0

cisco ios xr 3.7.3

cisco ios xr 3.7.2

cisco ios xr 3.5.4

cisco ios xr 3.5.3

cisco ios xr 4.3.4

cisco ios xr 4.3.2

cisco ios xr 4.0.4

cisco ios xr 4.0.3

cisco ios xr 3.8.4

cisco ios xr 3.8.3

cisco ios xr 3.6.3

cisco ios xr 3.6.2

cisco ios xr 3.5

cisco ios xr 3.4.3

cisco ios xr 3.3.2

cisco ios xr 3.3.1

cisco ios xr 3.1

cisco ios xr 3.0.1

cisco ios xr 4.3.1

cisco ios xr 4.3.0

cisco ios xr 4.0.2

cisco ios xr 4.0.1

cisco ios xr 3.8.2

cisco ios xr 3.8.1

cisco ios xr 3.6.1

cisco ios xr 3.6

cisco ios xr 3.4.2

cisco ios xr 3.4.1

cisco ios xr 3.3

cisco ios xr 3.2.50

cisco ios xr 3.0

cisco ios xr 2.0

cisco ios xr 3.4

cisco ios xr 3.3.5

cisco ios xr 3.2.4

cisco ios xr 3.2.2

cisco ios xr 3.2.1

cisco ios xr 5.1.0

cisco ios xr 4.1.1

cisco ios xr 4.1

cisco ios xr 3.9.1

cisco ios xr 3.9.0

cisco ios xr 3.7.1

cisco ios xr 3.7

cisco ios xr 3.5.2

cisco ios xr 3.5.1

cisco ios xr 3.3.4

cisco ios xr 3.3.3

cisco ios xr 3.2

cisco ios xr 3.1.0

Vendor Advisories

A vulnerability in TACACS+ processing of Cisco IOS XR could allow an unauthenticated, remote attacker to cause a reload of the TACACS+ daemon (tacacsd) on the affected device The vulnerability is due to improper parsing of a malformed TACACS+ packet An attacker could exploit this vulnerability by sending a malformed TACACS+ packet to be processe ...