CVE-2014-3361
published 2014-09-25CVE-2014-3361: The ALG module in Cisco IOS 15.0 through 15.4 does not properly implement SIP over NAT, which allows remote attackers to cause a denial of service (device…
PriorityP430high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
2.37%
82.0th percentile
The ALG module in Cisco IOS 15.0 through 15.4 does not properly implement SIP over NAT, which allows remote attackers to cause a denial of service (device reload) via multipart SDP IPv4 traffic, aka Bug ID CSCun54071.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7c87-x77q-chcq: The ALG module in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2014-3361 [HIGH] CWE-119 GHSA-7c87-x77q-chcq: The ALG module in Cisco IOS 15
The ALG module in Cisco IOS 15.0 through 15.4 does not properly implement SIP over NAT, which allows remote attackers to cause a denial of service (device reload) via multipart SDP IPv4 traffic, aka Bug ID CSCun54071.
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
Cisco
Cisco IOS Software Network Address Translation Denial of Service Vulnerability
vendor_cisco·2014-09-24·CVSS 7.1
CVE-2014-3361 [HIGH] CWE-20 Cisco IOS Software Network Address Translation Denial of Service Vulnerability
Cisco IOS Software Network Address Translation Denial of Service Vulnerability
A vulnerability in the Network Address Translation (NAT) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper translation of IP version 4 (IPv4) packets.
Cisco has released software updates that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140924-nat
Note: The September 24, 2014, Cisco IOS Software Security Advisory bundled publication includes six Cisco Security Advisories. All advisories address vulnerabilities in Cisco IOS Software. Individual publication li
Cisco
Cisco IOS Software Network Address Translation Denial of Service Vulnerability
vendor_cisco
CVE-2014-3361 Cisco IOS Software Network Address Translation Denial of Service Vulnerability
CVE-2014-3361: Cisco IOS Software Network Address Translation Denial of Service Vulnerability
A vulnerability in the Network Address Translation (NAT) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper translation of IP version 4 (IPv4) packets. Cisco has released software updates that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140924-nat Note: The September 24, 2014, Cisco IOS Software Security Advisory bundled publication includes six Cisco Security Advisories. All advisories address vulnerabilities in Cisco IOS Software. Individual pub
No detection rules found.
No public exploits indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140924-nathttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140924-nat/cvrf/cisco-sa-20140924-nat_cvrf.xmlhttp://www.securityfocus.com/bid/70129http://www.securitytracker.com/id/1030896https://exchange.xforce.ibmcloud.com/vulnerabilities/96181http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140924-nathttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140924-nat/cvrf/cisco-sa-20140924-nat_cvrf.xmlhttp://www.securityfocus.com/bid/70129http://www.securitytracker.com/id/1030896https://exchange.xforce.ibmcloud.com/vulnerabilities/96181
2014-09-25
Published