SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3290

The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the network or overwrite networking-services data via a…

MEDIUM 4.8EPSS 1.15%

Does this matter?

Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.

Description

The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the network or overwrite networking-services data via a crafted mDNS response, aka Bug ID CSCun64867.

CVSS 2.0
4.8 MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:N
EPSS
1.15% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
cisco/ios xe
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.