CVE-2014-3405 describes a vulnerability in Cisco IOS XE where the IPv6 Routing Protocol for Low-Power and Lossy Networks (RPL) is inadvertently enabled on both internal and external interfaces. This misconfiguration allows remote attackers to perform route-injection attacks by sending specially crafted RPL advertisements through the external Autonomic Networking Infrastructure (ANI) interface. The vulnerability has a CVSS score of 4.8, indicating a medium severity, with an adjacent network attack vector, low complexity, and potential for partial integrity and availability impact. There is no known exploit code available in Metasploit, Nuclei, or ExploitDB, and it has not been added to CISA's KEV catalog. The vulnerability has garnered minimal community discussion and media coverage, suggesting a low level of public attention and no indication of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:L/Au:N/C:N/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.