CVE-2014-8005

Cisco IOS XR < 5.1.0 - Denial of Service via Lighttpd TCP Session Race Condition

Title source: llm
STIX 2.1

Description

Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71287
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031262
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98937

Scores

EPSS 0.0119
EPSS Percentile 64.0%

Details

CWE
CWE-362
Status published
Products (1)
cisco/ios_xr < 5.1.0
Published Nov 26, 2014
Tracked Since Feb 18, 2026