Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-3402


The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug ID CSCuq39550.


Published

2014-10-10T10:55:06.727

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco intrusion_prevention_system ≤ 7.0\(8\)e4 Yes
Application cisco intrusion_prevention_system 7.0 Yes
Application cisco intrusion_prevention_system 7.0\(1\)e3 Yes
Application cisco intrusion_prevention_system 7.0\(2\)e3 Yes
Application cisco intrusion_prevention_system 7.0\(2\)e4 Yes
Application cisco intrusion_prevention_system 7.0\(3\)e4 Yes
Application cisco intrusion_prevention_system 7.0\(4\)e4 Yes
Application cisco intrusion_prevention_system 7.0\(5a\)e4 Yes
Application cisco intrusion_prevention_system 7.0\(6\)e4 Yes
Application cisco intrusion_prevention_system 7.0\(7\)e4 Yes

References