CVE-2014-3276

CWE-3994 documents4 sources
Severity
4.0MEDIUM
EPSS
0.6%
top 30.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26
Latest updateMay 17

Description

Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service (RADIUS outage) by sourcing these packets from two origins, aka Bug ID CSCuo56780.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-wg88-5525-mfh3: Cisco Identity Services Engine (ISE) 12022-05-17
CVEList
CVE-2014-3276: Cisco Identity Services Engine (ISE) 12014-05-23

📋Vendor Advisories

1
Cisco
Cisco Identity Services Engine RADIUS Service Denial of Service Vulnerability2014-05-22
CVE-2014-3276 (MEDIUM CVSS 4) | Cisco Identity Services Engine (ISE | cvebase.io