CVE-2014-2143

UnknownEPSS 1.73%

Last modified

CVE-2014-2143 is a vulnerability of currently unknown severity. The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021.. EPSS estimates a 1.73% chance of exploitation in the next 30 days.

Description

The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021.

Metrics

EPSS Probability
1.73%

74.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CiscoIos<= 15.4\(1\)t
CiscoIos15.0
CiscoIos15.0\(1\)se
CiscoIos15.1
CiscoIos15.2
CiscoIos15.3
CiscoIos15.3\(2\)s
CiscoIos15.3\(3\)m
CiscoIos15.3\(3\)m1
CiscoIos15.3\(3\)m2
CiscoIos15.3\(3\)s
CiscoIos15.3s
CiscoIos15.4
CiscoIos XeAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-2143?
The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021.
How severe is CVE-2014-2143?
Severity scoring for CVE-2014-2143 is pending analysis. The EPSS model estimates a 1.73% probability of exploitation in the next 30 days.
How do I fix CVE-2014-2143?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-2143?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST