Vulnerability Name: | CVE-2014-3385 (CCN-96857) | ||||||||
Assigned: | 2014-10-08 | ||||||||
Published: | 2014-10-08 | ||||||||
Updated: | 2014-10-12 | ||||||||
Summary: | Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8.3 before 8.3(2.42), 8.4 before 8.4(7.11), 8.5 before 8.5(1.19), 8.6 before 8.6(1.13), 8.7 before 8.7(1.11), 9.0 before 9.0(4.8), and 9.1 before 9.1(4.5) allows remote attackers to cause a denial of service (device reload) via TCP traffic that triggers many half-open connections at the same time, aka Bug ID CSCum00556. | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-362 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3385 Source: CCN Type: cisco-sa-20141008-asa Multiple Vulnerabilities in Cisco ASA Software Source: CISCO Type: Vendor Advisory 20141008 Multiple Vulnerabilities in Cisco ASA Software Source: CCN Type: BID-70298 Cisco Adaptive Security Appliance (ASA) Software CVE-2014-3385 Denial of Service Vulnerability Source: XF Type: UNKNOWN cisco-asa-cve20143385-dos(96857) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |