CVE detail
CVE-2014-3396 — CVE-2014-3396
Published 2014-10-05 · Modified 2026-06-17 · Vendor cisco · Product ios_xr · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0136
EPSS probability
exploitation probability, 30d
69.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass intended Typhoon line-card ACL restrictions via transit traffic, aka Bug ID CSCup30133.
Remediation
| Product | Vulnerable range | Fixed version | Advisory |
|---|
| n/a n/a | — | not specified | advisory ↗ |
References