ID

VAR-201407-0385


CVE

CVE-2014-3322


TITLE

Cisco ASR 9000 Run on device Cisco IOS XR Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-003559

DESCRIPTION

Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which allows remote attackers to cause a denial of service (chip and card hangs) via malformed (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCuo68417. Cisco IOS XR is a member of the Cisco IOS Software family that uses a microkernel-based operating system architecture. Attackers can exploit this issue to cause the NP chip and a line card on an affected device to lock up and reload, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCuo68417. The vulnerability is caused by the fact that the program does not perform sampling of NetFlow IP packets

Trust: 2.52

sources: NVD: CVE-2014-3322 // JVNDB: JVNDB-2014-003559 // CNVD: CNVD-2014-04684 // BID: 68833 // VULHUB: VHN-71262

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-04684

AFFECTED PRODUCTS

vendor:ciscomodel:ios xrscope:eqversion:4.3.1

Trust: 1.6

vendor:ciscomodel:ios xrscope:eqversion:4.3.0

Trust: 1.6

vendor:ciscomodel:asr 9000 rsp440 routerscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 9001scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:ios xrscope:lteversion:4.3.2

Trust: 1.0

vendor:ciscomodel:asr 9010scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 9912scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 9922scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 9006scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 9904scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:asr 9000 series rsp440scope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 9001 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 9006 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 9010 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 9904 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 9912 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:asr 9922 routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:ios xrscope:lteversion:4.3(.2)

Trust: 0.8

vendor:ciscomodel:ios xr softwarescope: - version: -

Trust: 0.6

vendor:ciscomodel:ios xrscope:eqversion:4.3.2

Trust: 0.6

sources: CNVD: CNVD-2014-04684 // JVNDB: JVNDB-2014-003559 // CNNVD: CNNVD-201407-601 // NVD: CVE-2014-3322

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3322
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-3322
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-04684
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201407-601
value: MEDIUM

Trust: 0.6

VULHUB: VHN-71262
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-3322
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-04684
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-71262
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-04684 // VULHUB: VHN-71262 // JVNDB: JVNDB-2014-003559 // CNNVD: CNNVD-201407-601 // NVD: CVE-2014-3322

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-71262 // JVNDB: JVNDB-2014-003559 // NVD: CVE-2014-3322

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201407-601

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201407-601

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-003559

PATCH

title:Cisco IOS XR Software NetFlow Processing Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3322

Trust: 0.8

title:35009url:http://tools.cisco.com/security/center/viewAlert.x?alertId=35009

Trust: 0.8

title:Cisco IOS XR Software NetFlow Patch for Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/47962

Trust: 0.6

sources: CNVD: CNVD-2014-04684 // JVNDB: JVNDB-2014-003559

EXTERNAL IDS

db:NVDid:CVE-2014-3322

Trust: 3.4

db:BIDid:68833

Trust: 2.0

db:SECUNIAid:60311

Trust: 1.7

db:SECTRACKid:1030623

Trust: 1.1

db:JVNDBid:JVNDB-2014-003559

Trust: 0.8

db:CNVDid:CNVD-2014-04684

Trust: 0.6

db:CNNVDid:CNNVD-201407-601

Trust: 0.6

db:VULHUBid:VHN-71262

Trust: 0.1

sources: CNVD: CNVD-2014-04684 // VULHUB: VHN-71262 // BID: 68833 // JVNDB: JVNDB-2014-003559 // CNNVD: CNNVD-201407-601 // NVD: CVE-2014-3322

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-3322

Trust: 2.3

url:http://tools.cisco.com/security/center/viewalert.x?alertid=35009

Trust: 1.7

url:http://secunia.com/advisories/60311

Trust: 1.7

url:http://www.securityfocus.com/bid/68833

Trust: 1.1

url:http://www.securitytracker.com/id/1030623

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3322

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-3322

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2014-04684 // VULHUB: VHN-71262 // BID: 68833 // JVNDB: JVNDB-2014-003559 // CNNVD: CNNVD-201407-601 // NVD: CVE-2014-3322

CREDITS

Cisco

Trust: 0.3

sources: BID: 68833

SOURCES

db:CNVDid:CNVD-2014-04684
db:VULHUBid:VHN-71262
db:BIDid:68833
db:JVNDBid:JVNDB-2014-003559
db:CNNVDid:CNNVD-201407-601
db:NVDid:CVE-2014-3322

LAST UPDATE DATE

2024-11-23T21:45:00.977000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-04684date:2014-07-30T00:00:00
db:VULHUBid:VHN-71262date:2017-01-12T00:00:00
db:BIDid:68833date:2014-07-24T00:17:00
db:JVNDBid:JVNDB-2014-003559date:2014-07-25T00:00:00
db:CNNVDid:CNNVD-201407-601date:2014-07-25T00:00:00
db:NVDid:CVE-2014-3322date:2024-11-21T02:07:51.870

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-04684date:2014-07-29T00:00:00
db:VULHUBid:VHN-71262date:2014-07-24T00:00:00
db:BIDid:68833date:2014-07-22T00:00:00
db:JVNDBid:JVNDB-2014-003559date:2014-07-25T00:00:00
db:CNNVDid:CNNVD-201407-601date:2014-07-25T00:00:00
db:NVDid:CVE-2014-3322date:2014-07-24T14:55:07.723