Cisco ios xe Software Security Vulnerability (CVE-2014-3405)
Release date: 2014-10-09
Updated on:
Affected Systems:
Cisco IOS XE
Description:
Bugtraq id: 70385
CVE (CAN) ID: CVE-2014-3405
Cisco IOS is an interconnected network operating system used on most Cisco system routers and network switches.
Cisco ios xe Software enables the IPv6 RPL protocol on the ACP and ANI interfaces. Remote attackers can exploit this vulnerability to inject routing attacks to the ANI interfaces by constructing RPL advertisements through the ANI interfaces.
<* Source: Cisco
*>
Suggestion:
Vendor patch:
Cisco
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://tools.cisco.com/security/center/publicationListing.x #~ CiscoSecurityResponse
Http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3405
This article permanently updates the link address: