CVE-2014-3321: Cisco Asr 9000 RSP440 Router

Medium severity, CVSS 5.7. EPSS: 0.6% chance of exploitation in the next 30 days.

Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149.

Affected products

  • Cisco Asr 9000 RSP440 Router
  • Cisco Asr 9001
  • Cisco Asr 9006
  • Cisco Asr 9010
  • Cisco Asr 9904
  • Cisco Asr 9912
  • Cisco Asr 9922
  • Cisco IOS XR: up to and including 4.3.4; version 4.3.0 only; version 4.3.1 only; version 4.3.2 only

Published 2014-07-18. Last modified 2026-06-17.