CVE-2014-2106: Cisco IOS

High severity, CVSS 7.8. EPSS: 2.4% chance of exploitation in the next 30 days.

Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCug45898.

Affected products

  • Cisco IOS: version 15.3(3)m only; version 15.3(3)m1 only
  • Cisco IOS XE: version 3.10.0s only; version 3.10.1s1 only

Published 2014-03-27. Last modified 2026-06-17.