CVE-2014-3295
Last modified
CVE-2014-3295 is a vulnerability of currently unknown severity. The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.. EPSS estimates a 1.12% chance of exploitation in the next 30 days.
Description
The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Nx-Os | <= 6.2\(2a\) |
| Cisco | Nx-Os | 4.1.\(2\) |
| Cisco | Nx-Os | 4.1.\(3\) |
| Cisco | Nx-Os | 4.1.\(4\) |
| Cisco | Nx-Os | 4.1.\(5\) |
| Cisco | Nx-Os | 4.2\(3\) |
| Cisco | Nx-Os | 4.2\(4\) |
| Cisco | Nx-Os | 4.2\(6\) |
| Cisco | Nx-Os | 4.2\(8\) |
| Cisco | Nx-Os | 4.2.\(2a\) |
| Cisco | Nx-Os | 5.0\(2a\) |
| Cisco | Nx-Os | 5.0\(3\) |
| Cisco | Nx-Os | 5.0\(5\) |
| Cisco | Nx-Os | 5.1\(1a\) |
| Cisco | Nx-Os | 5.1\(3\) |
| Cisco | Nx-Os | 5.1\(4\) |
| Cisco | Nx-Os | 5.1\(5\) |
| Cisco | Nx-Os | 5.1\(6\) |
| Cisco | Nx-Os | 5.2\(1\) |
| Cisco | Nx-Os | 5.2\(3a\) |
| Cisco | Nx-Os | 5.2\(4\) |
| Cisco | Nx-Os | 5.2\(5\) |
| Cisco | Nx-Os | 5.2\(7\) |
| Cisco | Nx-Os | 5.2\(9\) |
| Cisco | Nx-Os | 6.0\(1\) |
| Cisco | Nx-Os | 6.0\(2\) |
| Cisco | Nx-Os | 6.0\(3\) |
| Cisco | Nx-Os | 6.0\(4\) |
| Cisco | Nx-Os | 6.1\(1\) |
| Cisco | Nx-Os | 6.1\(2\) |
| Cisco | Nx-Os | 6.1\(3\) |
| Cisco | Nx-Os | 6.1\(4\) |
| Cisco | Nx-Os | 6.1\(4a\) |
| Cisco | Nx-Os | 6.2\(2\) |
References
- http://secunia.com/advisories/59158Permissions Required
- http://www.securityfocus.com/bid/67983Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030409Third Party Advisory, VDB Entry
- http://secunia.com/advisories/59158Permissions Required
- http://www.securityfocus.com/bid/67983Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030409Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3295?
How severe is CVE-2014-3295?
How do I fix CVE-2014-3295?
Are you affected by CVE-2014-3295?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
