CVE-2014-3385
published 2014-10-10CVE-2014-3385: Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8.3 before 8.3(2.42), 8.4 before 8.4(7.11), 8.5 before…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.01%
59.0th percentile
Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8.3 before 8.3(2.42), 8.4 before 8.4(7.11), 8.5 before 8.5(1.19), 8.6 before 8.6(1.13), 8.7 before 8.7(1.11), 9.0 before 9.0(4.8), and 9.1 before 9.1(4.5) allows remote attackers to cause a denial of service (device reload) via TCP traffic that triggers many half-open connections at the same time, aka Bug ID CSCum00556.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco·2014-10-08·CVSS 7.8
CVE-2014-3382 [HIGH] CWE-16 Multiple Vulnerabilities in Cisco ASA Software
Multiple Vulnerabilities in Cisco ASA Software
2015-July-08 UPDATE: Cisco PSIRT is aware of disruption to some
Cisco customers with Cisco ASA devices affected by CVE-2014-3383, the
Cisco ASA VPN Denial of Service Vulnerability that was disclosed in this
Security Advisory. Traffic causing the disruption was isolated to a
specific source IPv4 address. Cisco has engaged the provider and owner
of that device and determined that the traffic was sent with no
malicious intent. Cisco strongly recommends that customers upgrade to a
fixed Cisco ASA software release to remediate this issue.
Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities:
Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability
Cisco ASA VPN Denial of Service Vulnerability
C
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco
CVE-2014-3385 Multiple Vulnerabilities in Cisco ASA Software
CVE-2014-3385: Multiple Vulnerabilities in Cisco ASA Software
2015-July-08 UPDATE: Cisco PSIRT is aware of disruption to some Cisco customers with Cisco ASA devices affected by CVE-2014-3383, the Cisco ASA VPN Denial of Service Vulnerability that was disclosed in this Security Advisory. Traffic causing the disruption was isolated to a specific source IPv4 address. Cisco has engaged the provider and owner of that device and determined that the traffic was sent with no malicious intent. Cisco strongly recommends that customers upgrade to a fixed Cisco ASA software release to remediate this issue. Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities: Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability Cisco ASA VPN Denial of Service Vul
GHSA
GHSA-6fm8-px7c-8gm4: Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8
ghsa_unreviewed·2022-05-17
CVE-2014-3385 [HIGH] CWE-362 GHSA-6fm8-px7c-8gm4: Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8
Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8.3 before 8.3(2.42), 8.4 before 8.4(7.11), 8.5 before 8.5(1.19), 8.6 before 8.6(1.13), 8.7 before 8.7(1.11), 9.0 before 9.0(4.8), and 9.1 before 9.1(4.5) allows remote attackers to cause a denial of service (device reload) via TCP traffic that triggers many half-open connections at the same time, aka Bug ID CSCum00556.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-10-10
Published