CVE-2014-3347
published 2014-08-28CVE-2014-3347: Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device…
PriorityP425medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
0.98%
58.0th percentile
Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid state of the hardware encryption module, aka Bug ID CSCul77897.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
vendor_cisco5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco 1800 Series ISR ISDN Basic Rate Interface Denial of Service Vulnerability
vendor_cisco·2014-08-28·CVSS 5.4
CVE-2014-3347 [MEDIUM] CWE-399 Cisco 1800 Series ISR ISDN Basic Rate Interface Denial of Service Vulnerability
Cisco 1800 Series ISR ISDN Basic Rate Interface Denial of Service Vulnerability
Cisco 1800 Series Integrated Services Routers (ISR) contain a vulnerability in the hardware entropy collection module when the Integrated Services Digital Network (ISDN) Basic Rate Interface (BRI) is configured and connected to a public switched network. This could allow an attacker with knowledge of the ISDN phone number of the affected device to trigger a denial of service (DoS) condition.
The vulnerability is due to an interrupt timer collision that causes the hardware encryption module to enter a corrupted state, causing the device to become unresponsive. An attacker would need to perform the attack exactly when the device polls the hardware encryption module to perform entropy collection.
The affected d
GHSA
GHSA-w2gc-qf48-fjxq: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2014-3347 [MEDIUM] GHSA-w2gc-qf48-fjxq: Cisco IOS 15
Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid state of the hardware encryption module, aka Bug ID CSCul77897.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3347http://tools.cisco.com/security/center/viewAlert.x?alertId=35453http://www.securityfocus.com/bid/69439http://www.securitytracker.com/id/1030772https://exchange.xforce.ibmcloud.com/vulnerabilities/95558http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3347http://tools.cisco.com/security/center/viewAlert.x?alertId=35453http://www.securityfocus.com/bid/69439http://www.securitytracker.com/id/1030772https://exchange.xforce.ibmcloud.com/vulnerabilities/95558
2014-08-28
Published