CVE-2014-2183
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
29/04/2014
Last modified:
12/04/2025
Description
The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP packet, aka Bug ID CSCun09973.
Impact
Base Score 2.0
6.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* | 3.10.2s (including) | |
| cpe:2.3:o:cisco:ios_xe:3.10:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:3.10.0s:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:3.10.1s:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:ios_xe:3.10.1s1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1001:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1002:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1002-x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1002_fixed_router:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1004:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1006:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1013:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cisco:asr_1023_router:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



