CVE-2014-2112
published 2014-03-27CVE-2014-2112: The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.00%
78.7th percentile
The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP requests, aka Bug ID CSCuf51357.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco IOS 15.1/15.2/15.3/15.4 SSL VPN HTTP input validation (cisco-sa-20140326-ios-sslvpn / Nessus ID 73342)
vuldb·2026-05-09·CVSS 7.8
CVE-2014-2112 [HIGH] Cisco IOS 15.1/15.2/15.3/15.4 SSL VPN HTTP input validation (cisco-sa-20140326-ios-sslvpn / Nessus ID 73342)
A vulnerability was found in Cisco IOS 15.1/15.2/15.3/15.4. It has been classified as problematic. This impacts an unknown function of the component SSL VPN HTTP Handler. This manipulation causes improper input validation.
This vulnerability appears as CVE-2014-2112. The attack may be initiated remotely. There is no available exploit.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-8gr9-f6w2-pprx: The SSL VPN (aka WebVPN) feature in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2014-2112 [HIGH] CWE-20 GHSA-8gr9-f6w2-pprx: The SSL VPN (aka WebVPN) feature in Cisco IOS 15
The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP requests, aka Bug ID CSCuf51357.
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
Cisco
Cisco IOS Software SSL VPN Denial of Service Vulnerability
vendor_cisco·2014-03-26·CVSS 7.8
CVE-2014-2112 [HIGH] CWE-399 Cisco IOS Software SSL VPN Denial of Service Vulnerability
Cisco IOS Software SSL VPN Denial of Service Vulnerability
A vulnerability in the Secure Sockets Layer (SSL) VPN subsystem of Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to a failure to process certain types of HTTP requests. To exploit the vulnerability, an attacker could submit crafted requests designed to consume memory to an affected device. An exploit could allow the attacker to consume and fragment memory on the affected device. This may cause reduced performance, a failure of certain processes, or a restart of the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds to mitigate this vulnerability.
This advisory is available at th
Cisco
Cisco IOS Software SSL VPN Denial of Service Vulnerability
vendor_cisco
CVE-2014-2112 Cisco IOS Software SSL VPN Denial of Service Vulnerability
CVE-2014-2112: Cisco IOS Software SSL VPN Denial of Service Vulnerability
A vulnerability in the Secure Sockets Layer (SSL) VPN subsystem of Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a failure to process certain types of HTTP requests. To exploit the vulnerability, an attacker could submit crafted requests designed to consume memory to an affected device. An exploit could allow the attacker to consume and fragment memory on the affected device. This may cause reduced performance, a failure of certain processes, or a restart of the affected device. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCuf51357, CSCuf51357
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-03-27
Published