CVE-2014-3322

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
24/07/2014
Last modified:
12/04/2025

Description

Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which allows remote attackers to cause a denial of service (chip and card hangs) via malformed (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCuo68417.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* 4.3.2 (including)
cpe:2.3:o:cisco:ios_xr:4.3.0:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:4.3.1:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_9000_rsp440_router:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_9001:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_9006:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_9010:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_9904:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_9912:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asr_9922:-:*:*:*:*:*:*:*