5
CVSSv2

CVE-2014-8005

Published: 26/11/2014 Updated: 08/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Race condition in the lighttpd module in Cisco IOS XR 5.1 and previous versions on Network Convergence System 6000 devices allows remote malicious users to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xr

Vendor Advisories

A vulnerability in the lighttpd module of Cisco IOS XR could allow an unauthenticated, remote attacker to cause a reload of the affected lighttpd process The vulnerability is due to a race condition while handling TCP sessions to the lighttpd module on the affected Cisco IOS XR device An attacker could exploit this vulnerability by sending a num ...