4.8
CVSSv2

CVE-2014-3405

Published: 10/10/2014 Updated: 10/10/2014
CVSS v2 Base Score: 4.8 | Impact Score: 4.9 | Exploitability Score: 6.5
VMScore: 427
Vector: AV:A/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Cisco IOS XE enables the IPv6 Routing Protocol for Low-Power and Lossy Networks (aka RPL) on both the Autonomic Control Plane (ACP) and external Autonomic Networking Infrastructure (ANI) interfaces, which allows remote malicious users to conduct route-injection attacks via crafted RPL advertisements on an ANI interface, aka Bug ID CSCuq22673.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe -

Vendor Advisories

A vulnerability in the IPv6 Routing Protocol for Low-Power and Lossy Networks (RPL) of Cisco IOS XE could allow an unauthenticated, adjacent attacker to inject routes into the autonomic control plane (ACP) The vulnerability is due to RPL being active on ACP as well as the external Autonomic Networking Infrastructure (ANI) interfaces An attacker ...