7.8

CVE-2014-3357

Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allow remote attackers to cause a denial of service (device reload) via malformed mDNS packets, aka Bug ID CSCul90866.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ios Version 15.0
Cisco ≫ Ios Version 15.1
Cisco ≫ Ios Version 15.2
Cisco ≫ Ios Version 15.4
Cisco ≫ Ios Xe Version 3.3.0se
Cisco ≫ Ios Xe Version 3.3.1se
Cisco ≫ Ios Xe Version 3.5.0e
Cisco ≫ Ios Xe Version 3.5.1e
Cisco ≫ Ios Xe Version 3.11.0s
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.85% 0.849
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140924-mdns
Vendor Advisory
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140924-mdns/cvrf/cisco-sa-20140924-mdns_cvrf.xml
http://www.securityfocus.com/bid/70132
http://www.securitytracker.com/id/1030898
https://exchange.xforce.ibmcloud.com/vulnerabilities/96182