CVE-2014-3262: Cisco IOS
Medium severity, CVSS 4.3. EPSS: 1.6% chance of exploitation in the next 30 days.
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of service (CEF outage and packet drops) via malformed messages, aka Bug ID CSCun73782.
Affected products
- Cisco IOS: up to and including 15.3\(3\)s; version 15.3(3)m only; version 15.3m only; version 15.3s only
- Cisco IOS XE: affected versions not specified
Published 2014-05-16. Last modified 2026-06-17.