CVE-2014-3262 describes a denial-of-service vulnerability in the Locator/ID Separation Protocol (LISP) implementation of Cisco IOS and IOS XE. Malformed ITR control messages can lead to a CEF outage and packet drops. Rated with a CVSS score of 4.3, this vulnerability has a network attack vector and medium attack complexity, potentially resulting in partial availability impact. There is no evidence of active exploitation, and no public exploit code or significant community discussion has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 15.3\(3\)sCPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* | ||
15.3\(3\)mCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.3\(3\)m:*:*:*:*:*:*:* | ||
15.3mCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.3m:*:*:*:*:*:*:* | ||
15.3sCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.3s:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.