Vulnerability Name: | CVE-2014-3331 (CCN-95357) | ||||||||
Assigned: | 2014-08-19 | ||||||||
Published: | 2014-08-19 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11.0, 12.0, 12.1, 12.2, 14.0, 15.0, 16.x through 16.1.2, and 17.0 allows remote attackers to cause a denial of service (process crash) via a crafted TCP packet, aka Bug ID CSCuo21914. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3331 Source: SECUNIA Type: UNKNOWN 60706 Source: CCN Type: Cisco Security Notice Cisco Packet Data Network Gateway Denial Of Service Vulnerability Source: CISCO Type: Vendor Advisory 20140819 Cisco Packet Data Network Gateway Denial of Service Vulnerability Source: CONFIRM Type: Vendor Advisory http://tools.cisco.com/security/center/viewAlert.x?alertId=35346 Source: BID Type: UNKNOWN 69281 Source: CCN Type: BID-69281 Cisco ASR 5000 Series Software CVE-2014-3331 Denial of Service Vulnerability Source: SECTRACK Type: UNKNOWN 1030747 Source: XF Type: UNKNOWN cisco-pgw-cve20143331-dos(95357) Source: XF Type: UNKNOWN cisco-pgw-cve20143331-dos(95357) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |