CVE-2014-3348
published 2014-09-10CVE-2014-3348: The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing System on E-Series blade servers allows remote attackers…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.58%
83.5th percentile
The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing System on E-Series blade servers allows remote attackers to cause a denial of service (IMC hang) via a crafted SSH packet, aka Bug ID CSCuo69206.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | integrated_management_controller | <= 2.2.2 | — |
| cisco | unified_computing_system_e-series_blade_servers_cisco_integrated_management_cont | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7v92-w294-rhvv: The SSH module in the Integrated Management Controller (IMC) before 2
ghsa_unreviewed·2022-05-17
CVE-2014-3348 [MEDIUM] CWE-20 GHSA-7v92-w294-rhvv: The SSH module in the Integrated Management Controller (IMC) before 2
The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing System on E-Series blade servers allows remote attackers to cause a denial of service (IMC hang) via a crafted SSH packet, aka Bug ID CSCuo69206.
Cisco
Cisco Unified Computing System E-Series Blade Servers Cisco Integrated Management Controller SSH Denial of Service Vulnerability
vendor_cisco·2014-09-08·CVSS 7.8
CVE-2014-3348 [HIGH] CWE-20 Cisco Unified Computing System E-Series Blade Servers Cisco Integrated Management Controller SSH Denial of Service Vulnerability
Cisco Unified Computing System E-Series Blade Servers Cisco Integrated Management Controller SSH Denial of Service Vulnerability
A vulnerability in the Cisco Integrated Management Controller (Cisco IMC) SSH module of the Cisco Unified Computing System E-Series Blade servers could allow an unauthenticated, remote attacker to cause a denial of service condition.
The vulnerability is due to a failure to properly handle a crafted SSH packet. An attacker could exploit this vulnerability by sending a crafted packet to the SSH server running on the Cisco IMC of an affected device, which could result in the Cisco IMC becoming unresponsive. The operating system running on the blade will be unaffected.
Cisco has released software updates that address this vulnerability
This advisory is available a
Cisco
Cisco Integrated Management Controller SSH Denial of Service Vulnerability
vendor_cisco·2014-09-05·CVSS 5.0
CVE-2014-3348 [MEDIUM] CWE-20 Cisco Integrated Management Controller SSH Denial of Service Vulnerability
Cisco Integrated Management Controller SSH Denial of Service Vulnerability
A vulnerability in the Cisco Integrated Management Controller (Cisco IMC) SSH module of the Cisco Unified Computing System E-Series Blade servers could allow an unauthenticated, remote attacker to cause a denial of service condition.
The vulnerability is due to a failure to properly handle a crafted SSH packet. An attacker could exploit this vulnerability by sending a crafted packet to the SSH server running on the Cisco IMC of an affected device, which could result in the Cisco IMC becoming unresponsive. The operating system running on the blade will be unaffected.
Cisco has confirmed the vulnerability in a security advisory and released software updates.
To exploit this vulnerability, an attacker may need acc
Cisco
Cisco Unified Computing System E-Series Blade Servers Cisco Integrated Management Controller SSH Denial of Service Vulnerability
vendor_cisco
CVE-2014-3348 Cisco Unified Computing System E-Series Blade Servers Cisco Integrated Management Controller SSH Denial of Service Vulnerability
CVE-2014-3348: Cisco Unified Computing System E-Series Blade Servers Cisco Integrated Management Controller SSH Denial of Service Vulnerability
A vulnerability in the Cisco Integrated Management Controller (Cisco IMC) SSH module of the Cisco Unified Computing System E-Series Blade servers could allow an unauthenticated, remote attacker to cause a denial of service condition. The vulnerability is due to a failure to properly handle a crafted SSH packet. An attacker could exploit this vulnerability by sending a crafted packet to the SSH server running on the Cisco IMC of an affected device, which could result in the Cisco IMC becoming unresponsive. The operating system running on the blade will be unaffected. Cisco has released software updates that address this vulnerability This advisory i
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140908-ucsehttp://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3348http://tools.cisco.com/security/center/viewAlert.x?alertId=35588http://www.securityfocus.com/bid/69652http://www.securitytracker.com/id/1030813https://exchange.xforce.ibmcloud.com/vulnerabilities/95782http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140908-ucsehttp://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3348http://tools.cisco.com/security/center/viewAlert.x?alertId=35588http://www.securityfocus.com/bid/69652http://www.securitytracker.com/id/1030813https://exchange.xforce.ibmcloud.com/vulnerabilities/95782
2014-09-10
Published