Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.105689
Category:CISCO
Title:Cisco IOS XR Software Malformed RSVP Packet Denial of Service Vulnerability
Summary:A vulnerability in RSVP processing of Cisco IOS XR could allow an unauthenticated, remote attacker to cause a reload of the RSVP process on the affected device.;;The vulnerability is due to improper parsing of a malformed RSVP packet. An attacker could exploit this vulnerability by sending a malformed RSVP packet to be processed by an affected device. An exploit could allow the attacker to cause a reload of the RSVP process on the affected device.;;Cisco has confirmed the vulnerability and released software updates.;;;To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send numerous TCP sessions to the targeted device. This access requirement may reduce the likelihood of a successful exploit.
Description:Summary:
A vulnerability in RSVP processing of Cisco IOS XR could allow an unauthenticated, remote attacker to cause a reload of the RSVP process on the affected device.

The vulnerability is due to improper parsing of a malformed RSVP packet. An attacker could exploit this vulnerability by sending a malformed RSVP packet to be processed by an affected device. An exploit could allow the attacker to cause a reload of the RSVP process on the affected device.

Cisco has confirmed the vulnerability and released software updates.


To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send numerous TCP sessions to the targeted device. This access requirement may reduce the likelihood of a successful exploit.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-8014
Cisco Security Advisory: 20141217 Cisco IOS XR Software Malformed RSVP Packet Denial of Service Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8014
http://www.securitytracker.com/id/1031396
CopyrightThis script is Copyright (C) 2016 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.