CVE-2014-3295: Cisco NX-OS
Medium severity, CVSS 4.8. EPSS: 1.1% chance of exploitation in the next 30 days.
The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.
Affected products
- Cisco NX-OS: up to and including 6.2\(2a\); version 4.1.(2) only; version 4.1.(3) only; version 4.1.(4) only; version 4.1.(5) only; version 4.2(3) only; …
Published 2014-06-14. Last modified 2026-06-17.