ID

VAR-201405-0346


CVE

CVE-2014-3273


TITLE

Cisco IOS of LLDP Service disruption in implementations (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-002556

DESCRIPTION

The LLDP implementation in Cisco IOS allows remote attackers to cause a denial of service (device reload) via a malformed packet, aka Bug ID CSCum96282. Cisco IOS is the interconnected network operating system used on most Cisco system routers and network switches. The LLDP packet is sent to the LLDP-enabled device to overload the affected device. Cisco IOS Software is prone to a remote denial-of-service vulnerability. Attackers can exploit this issue to cause the affected device to reload, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCum96282

Trust: 2.52

sources: NVD: CVE-2014-3273 // JVNDB: JVNDB-2014-002556 // CNVD: CNVD-2014-03189 // BID: 67489 // VULHUB: VHN-71213

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-03189

AFFECTED PRODUCTS

vendor:ciscomodel:iosscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:iosscope:eqversion:15.2(2)t

Trust: 0.8

vendor:ciscomodel:ios softwarescope: - version: -

Trust: 0.6

vendor:ciscomodel:ios 15.2tscope: - version: -

Trust: 0.3

vendor:ciscomodel:iosscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2014-03189 // BID: 67489 // JVNDB: JVNDB-2014-002556 // CNNVD: CNNVD-201405-390 // NVD: CVE-2014-3273

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3273
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-3273
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-03189
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201405-390
value: MEDIUM

Trust: 0.6

VULHUB: VHN-71213
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-3273
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-03189
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-71213
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-03189 // VULHUB: VHN-71213 // JVNDB: JVNDB-2014-002556 // CNNVD: CNNVD-201405-390 // NVD: CVE-2014-3273

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-71213 // JVNDB: JVNDB-2014-002556 // NVD: CVE-2014-3273

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201405-390

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201405-390

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-002556

PATCH

title:Cisco IOS Software LLDP Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3273

Trust: 0.8

title:34293url:http://tools.cisco.com/security/center/viewAlert.x?alertId=34293

Trust: 0.8

title:Cisco IOS Software LLDP Requests Patch for Handling Denial of Service Vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/45843

Trust: 0.6

sources: CNVD: CNVD-2014-03189 // JVNDB: JVNDB-2014-002556

EXTERNAL IDS

db:NVDid:CVE-2014-3273

Trust: 3.4

db:SECTRACKid:1030257

Trust: 1.1

db:BIDid:67489

Trust: 1.0

db:JVNDBid:JVNDB-2014-002556

Trust: 0.8

db:CNNVDid:CNNVD-201405-390

Trust: 0.7

db:CNVDid:CNVD-2014-03189

Trust: 0.6

db:CISCOid:20140519 CISCO IOS SOFTWARE LLDP DENIAL OF SERVICE VULNERABILITY

Trust: 0.6

db:VULHUBid:VHN-71213

Trust: 0.1

sources: CNVD: CNVD-2014-03189 // VULHUB: VHN-71213 // BID: 67489 // JVNDB: JVNDB-2014-002556 // CNNVD: CNNVD-201405-390 // NVD: CVE-2014-3273

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-3273

Trust: 2.3

url:http://www.securitytracker.com/id/1030257

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3273

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-3273

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2014-03189 // VULHUB: VHN-71213 // BID: 67489 // JVNDB: JVNDB-2014-002556 // CNNVD: CNNVD-201405-390 // NVD: CVE-2014-3273

CREDITS

Cisco

Trust: 0.3

sources: BID: 67489

SOURCES

db:CNVDid:CNVD-2014-03189
db:VULHUBid:VHN-71213
db:BIDid:67489
db:JVNDBid:JVNDB-2014-002556
db:CNNVDid:CNNVD-201405-390
db:NVDid:CVE-2014-3273

LAST UPDATE DATE

2025-04-12T23:05:06.912000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-03189date:2014-05-23T00:00:00
db:VULHUBid:VHN-71213date:2016-09-07T00:00:00
db:BIDid:67489date:2014-05-21T00:43:00
db:JVNDBid:JVNDB-2014-002556date:2014-05-21T00:00:00
db:CNNVDid:CNNVD-201405-390date:2014-05-23T00:00:00
db:NVDid:CVE-2014-3273date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-03189date:2014-05-23T00:00:00
db:VULHUBid:VHN-71213date:2014-05-20T00:00:00
db:BIDid:67489date:2014-05-19T00:00:00
db:JVNDBid:JVNDB-2014-002556date:2014-05-21T00:00:00
db:CNNVDid:CNNVD-201405-390date:2014-05-23T00:00:00
db:NVDid:CVE-2014-3273date:2014-05-20T11:13:38.343