CVE-2014-3396

Published Oct 5, 2014

Last updated 18 days ago

Overview

Description
Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass intended Typhoon line-card ACL restrictions via transit traffic, aka Bug ID CSCup30133.
Source
psirt@cisco.com
NVD status
Modified
Products
ios_xr, asr_9000_rsp440_router, asr_9001, asr_9006, asr_9010, asr_9904, asr_9912, asr_9922

Risk scores

CVSS 2.0

Type
Primary
Base score
7.5
Impact score
6.4
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-264

Social media

Hype score
Not currently trending

Configurations