CVE-2014-3331
published 2014-08-20CVE-2014-3331: The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11.0, 12.0, 12.1, 12.2, 14.0, 15.0, 16.x through…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.74%
75.0th percentile
The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11.0, 12.0, 12.1, 12.2, 14.0, 15.0, 16.x through 16.1.2, and 17.0 allows remote attackers to cause a denial of service (process crash) via a crafted TCP packet, aka Bug ID CSCuo21914.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.9MEDIUM
vendor_redhat5.5MEDIUM
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w2m9-fj8g-ffm2: The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11
ghsa_unreviewed·2022-05-17
CVE-2014-3331 [MEDIUM] CWE-20 GHSA-w2m9-fj8g-ffm2: The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11
The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11.0, 12.0, 12.1, 12.2, 14.0, 15.0, 16.x through 16.1.2, and 17.0 allows remote attackers to cause a denial of service (process crash) via a crafted TCP packet, aka Bug ID CSCuo21914.
OSV
linux-lts-utopic vulnerabilities
osv·2015-05-20·CVSS 6.9
CVE-2014-9710 linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)
A memory corruption issue was discovered in AES decryption when using the
Intel AES-NI accelerated code path. A remote attacker could exploit this
flaw to cause a denial of service (system crash) or potentially escalate
privileges on Intel base machines with AEC-GCM mode IPSec security
association. (CVE-2015-3331)
A flaw was discovered in the Linux kernel's IPv4 networking when using TCP
fast open to initiate a connection. An unprivileged local user could
exploit this flaw to cause a denial of service (system crash).
(CVE-2015-3332)
Cisco
Cisco Packet Data Network Gateway Denial of Service Vulnerability
vendor_cisco·2014-08-19·CVSS 4.3
CVE-2014-3331 [MEDIUM] CWE-20 Cisco Packet Data Network Gateway Denial of Service Vulnerability
Cisco Packet Data Network Gateway Denial of Service Vulnerability
A vulnerability in the Session Manager software of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to cause the Session Manager to crash.
The issue is due to insufficient validation of received TCP packets. An attacker could exploit this issue by sending a crafted TCP packet. An exploit could allow the attacker to cause the Session Manager process to crash.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send crafted TCP packets to the targeted device. This access requirement may reduce the likelihood of a successful exploit.
Cisc
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/60706http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3331http://tools.cisco.com/security/center/viewAlert.x?alertId=35346http://www.securityfocus.com/bid/69281http://www.securitytracker.com/id/1030747https://exchange.xforce.ibmcloud.com/vulnerabilities/95357http://secunia.com/advisories/60706http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3331http://tools.cisco.com/security/center/viewAlert.x?alertId=35346http://www.securityfocus.com/bid/69281http://www.securitytracker.com/id/1030747https://exchange.xforce.ibmcloud.com/vulnerabilities/95357
2014-08-20
Published