CVE-2014-3322
Description
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 suffers from a denial-of-service vulnerability via malformed IP packets due to improper NetFlow sampling.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 suffers from a denial-of-service vulnerability via malformed IP packets due to improper NetFlow sampling.
Vulnerability
Cisco IOS XR versions 4.3(.2) and earlier on ASR 9000 series devices improperly handle NetFlow sampling of IP packets. A remote attacker can send malformed IPv4 or IPv6 packets to cause a denial of service (chip and card hangs). This bug is tracked as CSCuo68417 [2].
Exploitation
An attacker needs network access to send malformed IPv4 or IPv6 packets to the device. No authentication is required. The malformed packets trigger a flaw in the NetFlow sampling process, leading to hangs of the chip and line card.
Impact
Successful exploitation results in a denial-of-service condition, causing chip and card hangs, which can disrupt network services. The device may become unresponsive until reset.
Mitigation
Cisco has not released a fix as of the publication date (2014-07-24). Workarounds are not disclosed in available references. Affected users should monitor Cisco's security advisories for updates.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
11- cpe:2.3:h:cisco:asr_9000_rsp440_router:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:asr_9001:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:asr_9006:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:asr_9010:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:asr_9904:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:asr_9912:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:asr_9922:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*range: <=4.3.2
- cpe:2.3:o:cisco:ios_xr:4.3.0:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios_xr:4.3.1:*:*:*:*:*:*:*
- (no CPE)range: <=4.3.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3322nvdVendor Advisory
- tools.cisco.com/security/center/viewAlert.xnvdVendor Advisory
- www.securityfocus.com/bid/68833nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1030623nvdThird Party AdvisoryVDB Entry
- secunia.com/advisories/60311nvd
News mentions
0No linked articles in our index yet.