CVE-2014-3330
published 2014-08-11CVE-2014-3330: Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers to bypass…
PriorityP430medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.13%
80.1th percentile
Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers to bypass intended access restrictions via a flood of packets matching a policy that contains the log keyword, aka Bug ID CSCuo02489.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6crj-4242-77vf: Cisco NX-OS 6
ghsa_unreviewed·2022-05-17
CVE-2014-3330 [MEDIUM] GHSA-6crj-4242-77vf: Cisco NX-OS 6
Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers to bypass intended access restrictions via a flood of packets matching a policy that contains the log keyword, aka Bug ID CSCuo02489.
Cisco
Cisco Nexus 9000 Series Switches Access List Bypass Vulnerability
vendor_cisco·2014-08-06·CVSS 5.0
CVE-2014-3330 [MEDIUM] CWE-264 Cisco Nexus 9000 Series Switches Access List Bypass Vulnerability
Cisco Nexus 9000 Series Switches Access List Bypass Vulnerability
A vulnerability in the implementation of the access list logging feature of Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to bypass the access list restriction for the logged traffic.
The vulnerability is due to insufficient policy checks for the logged packets. An attacker could exploit this vulnerability by sending a flood of denied packets that match an access list entry with the log keyword. An exploit could allow the attacker to bypass the access control list for a small percentage of the packets, which would otherwise have been dropped.
Cisco has confirmed the vulnerability in a security notice and released software updates.
Cisco indicates through the CVSS score that functional
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3330http://tools.cisco.com/security/center/viewAlert.x?alertId=35181http://www.securityfocus.com/bid/69057http://www.securitytracker.com/id/1030676https://exchange.xforce.ibmcloud.com/vulnerabilities/95122http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3330http://tools.cisco.com/security/center/viewAlert.x?alertId=35181http://www.securityfocus.com/bid/69057http://www.securitytracker.com/id/1030676https://exchange.xforce.ibmcloud.com/vulnerabilities/95122
2014-08-11
Published