Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of service (chip and card hangs) via a crafted packet, aka Bug ID CSCup77750.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/95443 | vdb entry |
http://www.securityfocus.com/bid/69383 | vdb entry |
http://secunia.com/advisories/60222 | third party advisory |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3335 | vendor advisory |
http://tools.cisco.com/security/center/viewAlert.x?alertId=35416 | vendor advisory |
http://www.securitytracker.com/id/1030757 | vdb entry |