ID

VAR-201405-0354


CVE

CVE-2014-3284


TITLE

Cisco IOS XE Software PPPoE Packet Handling Denial of Service Vulnerability

Trust: 0.9

sources: CNVD: CNVD-2014-03302 // BID: 67603

DESCRIPTION

Cisco IOS XE on ASR1000 devices, when PPPoE termination is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed PPPoE packet, aka Bug ID CSCuo55180. Vendors have confirmed this vulnerability Bug ID CSCuo55180 It is released as.Malformed by a third party PPPoE Service disruption via packets ( Device reload ) There is a possibility of being put into a state. Cisco IOS is the interconnected network operating system used on most Cisco system routers and network switches. Attackers can exploit this issue to cause the affected device to reload, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCuo55180

Trust: 2.52

sources: NVD: CVE-2014-3284 // JVNDB: JVNDB-2014-002631 // CNVD: CNVD-2014-03302 // BID: 67603 // VULHUB: VHN-71224

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-03302

AFFECTED PRODUCTS

vendor:ciscomodel:ios xescope:eqversion: -

Trust: 1.6

vendor:ciscomodel:asr 1004scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1006scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1002scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1023 routerscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1013scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1002 fixed routerscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1002-xscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1001scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 1001 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 1002 fixed routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 1002 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 1002-x routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 1004 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 1006 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 1013 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 1023 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:ios xescope:lteversion:3.7s(.2)

Trust: 0.8

vendor:ciscomodel:ios xescope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2014-03302 // JVNDB: JVNDB-2014-002631 // CNNVD: CNNVD-201405-468 // NVD: CVE-2014-3284

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3284
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-3284
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-03302
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201405-468
value: MEDIUM

Trust: 0.6

VULHUB: VHN-71224
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-3284
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-03302
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-71224
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-03302 // VULHUB: VHN-71224 // JVNDB: JVNDB-2014-002631 // CNNVD: CNNVD-201405-468 // NVD: CVE-2014-3284

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-71224 // JVNDB: JVNDB-2014-002631 // NVD: CVE-2014-3284

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201405-468

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-201405-468

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-002631

PATCH

title:Cisco IOS XE Software PPPoE Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3284

Trust: 0.8

title:34346url:http://tools.cisco.com/security/center/viewAlert.x?alertId=34346

Trust: 0.8

title:Cisco IOS XE Software PPPoE Packet Handling Patch for Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/45936

Trust: 0.6

title:Cisco IOS XE Enter the fix for the verification error vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=164613

Trust: 0.6

sources: CNVD: CNVD-2014-03302 // JVNDB: JVNDB-2014-002631 // CNNVD: CNNVD-201405-468

EXTERNAL IDS

db:NVDid:CVE-2014-3284

Trust: 3.4

db:BIDid:67603

Trust: 2.6

db:SECTRACKid:1030283

Trust: 1.7

db:SECUNIAid:58405

Trust: 1.7

db:JVNDBid:JVNDB-2014-002631

Trust: 0.8

db:CNNVDid:CNNVD-201405-468

Trust: 0.7

db:CNVDid:CNVD-2014-03302

Trust: 0.6

db:VULHUBid:VHN-71224

Trust: 0.1

sources: CNVD: CNVD-2014-03302 // VULHUB: VHN-71224 // BID: 67603 // JVNDB: JVNDB-2014-002631 // CNNVD: CNNVD-201405-468 // NVD: CVE-2014-3284

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-3284

Trust: 2.3

url:http://www.securityfocus.com/bid/67603

Trust: 2.3

url:http://tools.cisco.com/security/center/viewalert.x?alertid=34346

Trust: 1.7

url:http://www.securitytracker.com/id/1030283

Trust: 1.7

url:http://secunia.com/advisories/58405

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3284

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-3284

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2014-03302 // VULHUB: VHN-71224 // BID: 67603 // JVNDB: JVNDB-2014-002631 // CNNVD: CNNVD-201405-468 // NVD: CVE-2014-3284

CREDITS

Cisco

Trust: 0.3

sources: BID: 67603

SOURCES

db:CNVDid:CNVD-2014-03302
db:VULHUBid:VHN-71224
db:BIDid:67603
db:JVNDBid:JVNDB-2014-002631
db:CNNVDid:CNNVD-201405-468
db:NVDid:CVE-2014-3284

LAST UPDATE DATE

2024-11-23T21:55:20.930000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-03302date:2014-05-28T00:00:00
db:VULHUBid:VHN-71224date:2016-09-07T00:00:00
db:BIDid:67603date:2014-05-29T01:06:00
db:JVNDBid:JVNDB-2014-002631date:2014-05-28T00:00:00
db:CNNVDid:CNNVD-201405-468date:2021-10-08T00:00:00
db:NVDid:CVE-2014-3284date:2024-11-21T02:07:47.493

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-03302date:2014-05-28T00:00:00
db:VULHUBid:VHN-71224date:2014-05-25T00:00:00
db:BIDid:67603date:2014-05-23T00:00:00
db:JVNDBid:JVNDB-2014-002631date:2014-05-28T00:00:00
db:CNNVDid:CNNVD-201405-468date:2014-05-28T00:00:00
db:NVDid:CVE-2014-3284date:2014-05-25T22:55:02.393