CVE-2014-2103
published 2014-02-27CVE-2014-2103: Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP packets, aka…
PriorityP426medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
1.07%
60.9th percentile
Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP packets, aka Bug IDs CSCum52355 and CSCul49309.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IPS MainApp SNMP Denial of Service Vulnerability
vendor_cisco·2014-03-03·CVSS 6.8
CVE-2014-2103 [MEDIUM] CWE-20 Cisco IPS MainApp SNMP Denial of Service Vulnerability
Cisco IPS MainApp SNMP Denial of Service Vulnerability
A vulnerability in the SNMP code of Cisco Intrusion Prevention System (IPS) Software could allow an unauthenticated, remote attacker to cause the MainApp process to become unresponsive. This creates a denial of service (DoS) condition because the Cisco IPS sensor is not able to execute several critical tasks including alert notification, event store management, and sensor authentication. The Cisco IPS web server will also be unavailable while the MainApp process is unresponsive. Additionally, due to this general system failure, other processes such as the Analysis Engine may not function properly.
The vulnerability is due to improper handling of malformed SNMP packets. An attacker may exploit this vulnerability by sending malformed
GHSA
GHSA-8wf5-m44j-r94p: Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP pack
ghsa_unreviewed·2022-05-17
CVE-2014-2103 [MEDIUM] CWE-20 GHSA-8wf5-m44j-r94p: Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP pack
Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP packets, aka Bug IDs CSCum52355 and CSCul49309.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-02-27
Published