CVE-2014-3361: Cisco IOS

High severity, CVSS 7.1. EPSS: 2.4% chance of exploitation in the next 30 days.

The ALG module in Cisco IOS 15.0 through 15.4 does not properly implement SIP over NAT, which allows remote attackers to cause a denial of service (device reload) via multipart SDP IPv4 traffic, aka Bug ID CSCun54071.

Affected products

  • Cisco IOS: version 15.0 only; version 15.1 only; version 15.2 only; version 15.3 only; version 15.4 only

Published 2014-09-25. Last modified 2026-06-17.