ID

VAR-201404-0580


CVE

CVE-2014-2143


TITLE

Cisco IOS and IOS XE of IKE Service disruption in implementations (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-001912

DESCRIPTION

The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021. Cisco IOS is the interconnected network operating system used on most Cisco system routers and network switches. The fake IKE Main Mode packet was not processed correctly due to the program. This allows unauthenticated remote attackers to remove security associations that have already been established on the affected device. This issue is being tracked by Cisco Bug ID CSCun31021

Trust: 2.52

sources: NVD: CVE-2014-2143 // JVNDB: JVNDB-2014-001912 // CNVD: CNVD-2014-02163 // BID: 66628 // VULHUB: VHN-70082

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-02163

AFFECTED PRODUCTS

vendor:ciscomodel:iosscope:eqversion:15.3\(3\)m1

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:15.2

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:15.3\(3\)m2

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:15.3s

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:15.4

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:15.3\(2\)s

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:15.3\(3\)m

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:15.3

Trust: 1.6

vendor:ciscomodel:ios xescope:eqversion: -

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:15.3\(3\)s

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:15.1

Trust: 1.0

vendor:ciscomodel:iosscope:eqversion:15.0

Trust: 1.0

vendor:ciscomodel:iosscope:eqversion:15.0\(1\)se

Trust: 1.0

vendor:ciscomodel:iosscope:lteversion:15.4\(1\)t

Trust: 1.0

vendor:ciscomodel:iosscope:lteversion:15.4(1)t

Trust: 0.8

vendor:ciscomodel:ios xescope: - version: -

Trust: 0.8

vendor:ciscomodel:iosscope: - version: -

Trust: 0.6

vendor:ciscomodel:ios xe softwarescope: - version: -

Trust: 0.6

vendor:ciscomodel:iosscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2014-02163 // BID: 66628 // JVNDB: JVNDB-2014-001912 // CNNVD: CNNVD-201404-063 // NVD: CVE-2014-2143

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-2143
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-2143
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-02163
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201404-063
value: MEDIUM

Trust: 0.6

VULHUB: VHN-70082
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-2143
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-02163
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-70082
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-02163 // VULHUB: VHN-70082 // JVNDB: JVNDB-2014-001912 // CNNVD: CNNVD-201404-063 // NVD: CVE-2014-2143

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2014-2143

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201404-063

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201404-063

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001912

PATCH

title:Cisco IOS Software IKE Main Mode Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2143

Trust: 0.8

title:33639url:http://tools.cisco.com/security/center/viewAlert.x?alertId=33639

Trust: 0.8

title:Patch for Cisco IOS and IOS XE Software Denial of Service Vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/44680

Trust: 0.6

sources: CNVD: CNVD-2014-02163 // JVNDB: JVNDB-2014-001912

EXTERNAL IDS

db:NVDid:CVE-2014-2143

Trust: 3.4

db:BIDid:66628

Trust: 1.0

db:JVNDBid:JVNDB-2014-001912

Trust: 0.8

db:CNNVDid:CNNVD-201404-063

Trust: 0.7

db:CNVDid:CNVD-2014-02163

Trust: 0.6

db:CISCOid:20140403 CISCO IOS SOFTWARE IKE MAIN MODE VULNERABILITY

Trust: 0.6

db:VULHUBid:VHN-70082

Trust: 0.1

sources: CNVD: CNVD-2014-02163 // VULHUB: VHN-70082 // BID: 66628 // JVNDB: JVNDB-2014-001912 // CNNVD: CNNVD-201404-063 // NVD: CVE-2014-2143

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-2143

Trust: 2.3

url:http://tools.cisco.com/security/center/viewalert.x?alertid=33639

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-2143

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-2143

Trust: 0.8

url:http://www.cisco.com/public/sw-center/sw-ios.shtml

Trust: 0.3

sources: CNVD: CNVD-2014-02163 // VULHUB: VHN-70082 // BID: 66628 // JVNDB: JVNDB-2014-001912 // CNNVD: CNNVD-201404-063 // NVD: CVE-2014-2143

CREDITS

Cisco

Trust: 0.3

sources: BID: 66628

SOURCES

db:CNVDid:CNVD-2014-02163
db:VULHUBid:VHN-70082
db:BIDid:66628
db:JVNDBid:JVNDB-2014-001912
db:CNNVDid:CNNVD-201404-063
db:NVDid:CVE-2014-2143

LAST UPDATE DATE

2024-11-23T23:09:23.523000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-02163date:2014-04-08T00:00:00
db:VULHUBid:VHN-70082date:2014-04-04T00:00:00
db:BIDid:66628date:2014-04-08T00:57:00
db:JVNDBid:JVNDB-2014-001912date:2014-04-07T00:00:00
db:CNNVDid:CNNVD-201404-063date:2014-04-09T00:00:00
db:NVDid:CVE-2014-2143date:2024-11-21T02:05:44.103

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-02163date:2014-04-08T00:00:00
db:VULHUBid:VHN-70082date:2014-04-04T00:00:00
db:BIDid:66628date:2014-04-03T00:00:00
db:JVNDBid:JVNDB-2014-001912date:2014-04-07T00:00:00
db:CNNVDid:CNNVD-201404-063date:2014-04-09T00:00:00
db:NVDid:CVE-2014-2143date:2014-04-04T15:10:37.513