CVE-2014-3341
published 2014-08-19CVE-2014-3341: The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.70%
90.9th percentile
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | <= 7.0\(3\)n1\(1\) | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco NX-OS Software SNMP Information Disclosure Vulnerability
vendor_cisco·2014-08-18·CVSS 5.0
CVE-2014-3341 [MEDIUM] CWE-200 Cisco NX-OS Software SNMP Information Disclosure Vulnerability
Cisco NX-OS Software SNMP Information Disclosure Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) module of Cisco NX-OS Software could allow an unauthenticated, remote attacker to access sensitive information.
The vulnerability is due to a failure to respond to invalid requests in the same manner when specifying a VLAN ID. An attacker could exploit this vulnerability by making a large number of requests to the listening SNMP port of an affected device. A successful exploit could allow the attacker to enumerate VLANs that are configured on the affected device.
This vulnerability affects Cisco Nexus 5000 Series and Cisco Nexus 6000 Series devices running an affected version of Cisco NX-OS Software.
Cisco would like to thank Ehab Hussein of IOActive for disco
GHSA
GHSA-v8h5-6h8p-g3mg: The SNMP module in Cisco NX-OS 7
ghsa_unreviewed·2022-05-17
CVE-2014-3341 [MEDIUM] CWE-200 GHSA-v8h5-6h8p-g3mg: The SNMP module in Cisco NX-OS 7
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3341http://tools.cisco.com/security/center/viewAlert.x?alertId=35338http://www.securityfocus.com/bid/69266http://www.securitytracker.com/id/1030746https://exchange.xforce.ibmcloud.com/vulnerabilities/95329http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3341http://tools.cisco.com/security/center/viewAlert.x?alertId=35338http://www.securityfocus.com/bid/69266http://www.securitytracker.com/id/1030746https://exchange.xforce.ibmcloud.com/vulnerabilities/95329
2014-08-19
Published