Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted packets, aka Bug ID CSCun83985.
http://www.securitytracker.com/id/1030525
http://www.securityfocus.com/bid/68351
http://tools.cisco.com/security/center/viewAlert.x?alertId=34843
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3308
http://secunia.com/advisories/58869
Source: Mitre, NVD
Published: 2014-07-07
Updated: 2025-04-12
Base Score: 6.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P
Severity: Medium
Base Score: 8.6
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Severity: High
EPSS: 0.01418