The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of service (CEF outage and packet drops) via malformed messages, aka Bug ID CSCun73782.
2014-05-16T11:12:01.040
2025-04-12T10:46:40.837
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | ios | ≤ 15.3\(3\)s | Yes |
Operating System | cisco | ios | 15.3\(3\)m | Yes |
Operating System | cisco | ios | 15.3m | Yes |
Operating System | cisco | ios | 15.3s | Yes |
Operating System | cisco | ios_xe | - | Yes |