Vulnerability Name: | CVE-2014-3358 (CCN-96183) | ||||||||
Assigned: | 2014-09-24 | ||||||||
Published: | 2014-09-24 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allows remote attackers to cause a denial of service (memory consumption, and interface queue wedge or device reload) via malformed mDNS packets, aka Bug ID CSCuj58950. | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-78 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3358 Source: CCN Type: cisco-sa-20140924-mdns Multiple Vulnerabilities in Cisco IOS Software Multicast Domain Name System Source: CISCO Type: Vendor Advisory 20140924 Multiple Vulnerabilities in Cisco IOS Software Multicast Domain Name System Source: CONFIRM Type: UNKNOWN http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140924-mdns/cvrf/cisco-sa-20140924-mdns_cvrf.xml Source: BID Type: UNKNOWN 70139 Source: CCN Type: BID-70139 Cisco IOS and IOS XE Software Multicast DNS Gateway Memory Leak Denial of Service Vulnerability Source: SECTRACK Type: UNKNOWN 1030898 Source: XF Type: UNKNOWN ciscoios-cve20143358-dos(96183) Source: XF Type: UNKNOWN ciscoios-cve20143358-dos(96183) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |