CVE-2014-3386
published 2014-10-10CVE-2014-3386: The GPRS Tunneling Protocol (GTP) inspection engine in Cisco ASA Software 8.2 before 8.2(5.51), 8.4 before 8.4(7.15), 8.7 before 8.7(1.13), 9.0 before…
PriorityP339high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.89%
77.1th percentile
The GPRS Tunneling Protocol (GTP) inspection engine in Cisco ASA Software 8.2 before 8.2(5.51), 8.4 before 8.4(7.15), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted series of GTP packets, aka Bug ID CSCum56399.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
| cisco | asa | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco·2014-10-08·CVSS 7.8
CVE-2014-3382 [HIGH] CWE-16 Multiple Vulnerabilities in Cisco ASA Software
Multiple Vulnerabilities in Cisco ASA Software
2015-July-08 UPDATE: Cisco PSIRT is aware of disruption to some
Cisco customers with Cisco ASA devices affected by CVE-2014-3383, the
Cisco ASA VPN Denial of Service Vulnerability that was disclosed in this
Security Advisory. Traffic causing the disruption was isolated to a
specific source IPv4 address. Cisco has engaged the provider and owner
of that device and determined that the traffic was sent with no
malicious intent. Cisco strongly recommends that customers upgrade to a
fixed Cisco ASA software release to remediate this issue.
Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities:
Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability
Cisco ASA VPN Denial of Service Vulnerability
C
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco
CVE-2014-3386 Multiple Vulnerabilities in Cisco ASA Software
CVE-2014-3386: Multiple Vulnerabilities in Cisco ASA Software
2015-July-08 UPDATE: Cisco PSIRT is aware of disruption to some Cisco customers with Cisco ASA devices affected by CVE-2014-3383, the Cisco ASA VPN Denial of Service Vulnerability that was disclosed in this Security Advisory. Traffic causing the disruption was isolated to a specific source IPv4 address. Cisco has engaged the provider and owner of that device and determined that the traffic was sent with no malicious intent. Cisco strongly recommends that customers upgrade to a fixed Cisco ASA software release to remediate this issue. Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities: Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability Cisco ASA VPN Denial of Service Vul
GHSA
GHSA-wgg5-8q5m-w7xf: The GPRS Tunneling Protocol (GTP) inspection engine in Cisco ASA Software 8
ghsa_unreviewed·2022-05-17
CVE-2014-3386 [HIGH] GHSA-wgg5-8q5m-w7xf: The GPRS Tunneling Protocol (GTP) inspection engine in Cisco ASA Software 8
The GPRS Tunneling Protocol (GTP) inspection engine in Cisco ASA Software 8.2 before 8.2(5.51), 8.4 before 8.4(7.15), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted series of GTP packets, aka Bug ID CSCum56399.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-10-10
Published