Cisco ios xr Software Package Parsing Denial of Service Vulnerability (CVE-2014-3335)
Release date:
Updated on:
Affected Systems:
Cisco IOS XR
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69383
CVE (CAN) ID: CVE-2014-3335
Cisco IOS is an interconnected network operating system used on most Cisco system routers and network switches.
The Cisco ios xr data packet parsing code used on the ASR 9000 Series Aggregation Service Router has a security vulnerability, unauthenticated, physically close attackers can exploit this vulnerability to lock and reload NP chips and line cards. This vulnerability is caused by a specific packet parsing error after NetFlow sampling is configured.
<* Source: Cisco
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3335
Http://tools.cisco.com/security/center/publicationListing.x #~ CiscoSecurityResponse
This article permanently updates the link address: