VYPR
Unrated severityNVD Advisory· Published Sep 20, 2014· Updated May 6, 2026

CVE-2014-3376

CVE-2014-3376

Description

Cisco IOS XR 5.1 and earlier is prone to a denial-of-service vulnerability via a malformed RSVP packet, causing a process reload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco IOS XR 5.1 and earlier is prone to a denial-of-service vulnerability via a malformed RSVP packet, causing a process reload.

Vulnerability

Cisco IOS XR versions 5.1 and earlier contain a vulnerability in the processing of Resource Reservation Protocol (RSVP) packets. A remote attacker can trigger a denial of service (DoS) by sending a specially crafted, malformed RSVP packet to an affected device. The vulnerability is tracked as Cisco bug ID CSCuq12031 [1].

Exploitation

An attacker can exploit this vulnerability by sending a malformed RSVP packet over the network to the targeted Cisco IOS XR device. No authentication is required, and the attacker does not need prior access to the device. The attack is conducted remotely, leveraging the network path to deliver the malicious packet. The specific sequence involves constructing an RSVP packet that violates protocol expectations, causing an error in the handling code [1].

Impact

Successful exploitation causes the affected Cisco IOS XR process to reload, resulting in a denial of service. This can disrupt network operations and require manual intervention to restore full functionality. The impact is limited to availability; there is no evidence of information disclosure or remote code execution [1].

Mitigation

Cisco has not yet released a software update that addresses this vulnerability. As a workaround, administrators may implement access control lists (ACLs) to filter or block malformed RSVP traffic. Users should monitor Cisco's security advisory page for future updates. No EOL status or KEV listing has been reported for this CVE [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

56
  • cpe:2.3:o:cisco:ios_xr:2.0:*:*:*:*:*:*:*+ 55 more
    • cpe:2.3:o:cisco:ios_xr:2.0:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.0:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.1.0:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.2.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.2.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.2.4:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.2.50:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.3:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.3.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.3.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.3.3:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.3.4:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.3.5:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.4:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.4.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.4.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.4.3:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.5:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.5.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.5.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.5.3:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.5.4:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.6:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.6.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.6.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.6.3:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.7:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.7.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.7.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.7.3:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.8.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.8.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.8.3:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.8.4:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.9.0:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.9.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:3.9.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.0.0:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.0.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.0.3:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.0.4:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.1.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.1.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.2.0:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.3.0:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.3.1:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.3.2:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:4.3.4:*:*:*:*:*:*:*
    • cpe:2.3:o:cisco:ios_xr:5.1.0:*:*:*:*:*:*:*
    • (no CPE)range: <=5.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.