Cisco IOS and ios xe Software Denial of Service Vulnerability (CVE-2014-3409)
Release date:
Updated on:
Affected Systems:
Cisco IOS <= 12.2 (33) SRE9a
Description:
Bugtraq id: 70715
CVE (CAN) ID: CVE-2014-3409
Cisco IOS is an interconnected network operating system used on most Cisco system routers and network switches.
Cisco IOS 12.2 (33) SRE9a and earlier versions, ios xe 3.13S and earlier versions have security vulnerabilities in the implementation of Ethernet connection fault management (CFM, remote attackers exploit this vulnerability to cause DoS (device overload) by using malformed CFM packets ).
<* Source: Cisco
*>
Suggestion:
Vendor patch:
Cisco
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3409
Http://tools.cisco.com/security/center/viewAlert.x? AlertId = 36184
This article permanently updates the link address: