The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP packet, aka Bug ID CSCun09973.
2014-04-29T10:37:04.013
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.3 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:N/A:C
6.8
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | ios_xe | ≤ 3.10.2s | Yes |
Operating System | cisco | ios_xe | 3.10 | Yes |
Operating System | cisco | ios_xe | 3.10.0s | Yes |
Operating System | cisco | ios_xe | 3.10.1s | Yes |
Operating System | cisco | ios_xe | 3.10.1s1 | Yes |
Hardware | cisco | asr_1001 | - | Yes |
Hardware | cisco | asr_1002 | - | Yes |
Hardware | cisco | asr_1002-x | - | Yes |
Hardware | cisco | asr_1002_fixed_router | - | Yes |
Hardware | cisco | asr_1004 | - | Yes |
Hardware | cisco | asr_1006 | - | Yes |
Hardware | cisco | asr_1013 | - | Yes |
Hardware | cisco | asr_1023_router | - | Yes |