CVE-2014-3394
published 2014-10-10CVE-2014-3394: The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0…
PriorityP428medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.00%
58.8th percentile
The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to bypass certificate validation via an arbitrary VeriSign certificate, aka Bug ID CSCun10916.
Affected
71 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2p88-v9r5-p4mp: The Smart Call Home (SCH) implementation in Cisco ASA Software 8
ghsa_unreviewed·2022-05-17
CVE-2014-3394 [MEDIUM] CWE-295 GHSA-2p88-v9r5-p4mp: The Smart Call Home (SCH) implementation in Cisco ASA Software 8
The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to bypass certificate validation via an arbitrary VeriSign certificate, aka Bug ID CSCun10916.
Cisco
Cisco ASA Smart Call Home Digital Certificate Validation Vulnerability
vendor_cisco·2014-10-08·CVSS 5.0
CVE-2014-3394 [MEDIUM] CWE-16 Cisco ASA Smart Call Home Digital Certificate Validation Vulnerability
Cisco ASA Smart Call Home Digital Certificate Validation Vulnerability
A vulnerability in the
Smart Call Home (SCH) feature of Cisco ASA Software could allow an
unauthenticated, remote attacker to bypass digital certificate validation if any feature that uses digital certificates is configured on the affected system.
The
vulnerability exists because when SCH is configured, a
trustpoint, including a VeriSign certificate, is automatically installed. An attacker could exploit this vulnerability by presenting a valid
certificate signed by VeriSign when authenticating to the affected
system. An exploit could allow the attacker, for example, to bypass digital
certificate authentication when used by a given feature. Examples of
features that could be configured to use digital certificates valid
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco·2014-10-08·CVSS 7.8
CVE-2014-3382 [HIGH] CWE-16 Multiple Vulnerabilities in Cisco ASA Software
Multiple Vulnerabilities in Cisco ASA Software
2015-July-08 UPDATE: Cisco PSIRT is aware of disruption to some
Cisco customers with Cisco ASA devices affected by CVE-2014-3383, the
Cisco ASA VPN Denial of Service Vulnerability that was disclosed in this
Security Advisory. Traffic causing the disruption was isolated to a
specific source IPv4 address. Cisco has engaged the provider and owner
of that device and determined that the traffic was sent with no
malicious intent. Cisco strongly recommends that customers upgrade to a
fixed Cisco ASA software release to remediate this issue.
Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities:
Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability
Cisco ASA VPN Denial of Service Vulnerability
C
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco
CVE-2014-3394 Multiple Vulnerabilities in Cisco ASA Software
CVE-2014-3394: Multiple Vulnerabilities in Cisco ASA Software
2015-July-08 UPDATE: Cisco PSIRT is aware of disruption to some Cisco customers with Cisco ASA devices affected by CVE-2014-3383, the Cisco ASA VPN Denial of Service Vulnerability that was disclosed in this Security Advisory. Traffic causing the disruption was isolated to a specific source IPv4 address. Cisco has engaged the provider and owner of that device and determined that the traffic was sent with no malicious intent. Cisco strongly recommends that customers upgrade to a fixed Cisco ASA software release to remediate this issue. Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities: Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability Cisco ASA VPN Denial of Service Vul
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-10-10
Published