CVE-2014-3290
The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the network or overwrite networking-services data via a…
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the network or overwrite networking-services data via a crafted mDNS response, aka Bug ID CSCun64867.
- CVSS 2.0
- 4.8 MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/ios xe
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/58715Third Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3290Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34613Vendor Advisory
- http://www.securityfocus.com/bid/68021Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030444Third Party Advisory, VDB Entry
- http://secunia.com/advisories/58715Third Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3290Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34613Vendor Advisory
- http://www.securityfocus.com/bid/68021Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030444Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.