Vulnerability Name: | CVE-2014-3276 (CCN-93316) | ||||||||
Assigned: | 2014-05-21 | ||||||||
Published: | 2014-05-21 | ||||||||
Updated: | 2016-09-07 | ||||||||
Summary: | Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service (RADIUS outage) by sourcing these packets from two origins, aka Bug ID CSCuo56780. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-399 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3276 Source: CCN Type: Cisco Security Notice Cisco ISE RADIUS Service Denial of Service Vulnerability Source: CISCO Type: Vendor Advisory 20140521 Cisco ISE RADIUS Service Denial of Service Vulnerability Source: CONFIRM Type: Vendor Advisory http://tools.cisco.com/security/center/viewAlert.x?alertId=34329 Source: CCN Type: BID-67556 Cisco Identity Services Engine RADIUS Packet Processing Denial of Service Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1030274 Source: XF Type: UNKNOWN cisco-ise-cve20143276-dos(93316) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |