The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the network or overwrite networking-services data via a crafted mDNS response, aka Bug ID CSCun64867.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1030444 | third party advisory vdb entry |
http://secunia.com/advisories/58715 | third party advisory |
http://www.securityfocus.com/bid/68021 | third party advisory vdb entry |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3290 | vendor advisory |
http://tools.cisco.com/security/center/viewAlert.x?alertId=34613 | vendor advisory |