CVE-2014-3402
published 2014-10-10CVE-2014-3402: The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.34%
68.1th percentile
The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug ID CSCuq39550.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | intrusion_prevention_system | <= 7.0\(8\)e4 | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mxxp-82c5-w5g9: The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7
ghsa_unreviewed·2022-05-17
CVE-2014-3402 [MEDIUM] CWE-287 GHSA-mxxp-82c5-w5g9: The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7
The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug ID CSCuq39550.
Cisco
Cisco Intrusion Prevention System MainApp Denial of Service Vulnerability
vendor_cisco·2014-10-09·CVSS 5.0
CVE-2014-3402 [MEDIUM] CWE-287 Cisco Intrusion Prevention System MainApp Denial of Service Vulnerability
Cisco Intrusion Prevention System MainApp Denial of Service Vulnerability
A vulnerability in the web framework of Cisco Intrusion Prevention System (IPS) Software could allow
an authenticated, remote attacker to cause MainApp to hang
intermittently because the authentication manager process creates a
denial of service (DoS) condition.
The vulnerability is due to improper handling of user tokens. An
attacker could exploit this vulnerability by sending a crafted
connection request to the Cisco IPS management interface.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker must have authenticated access to the targeted system. This access requirement may reduce the likelihood of a successful exploit.
Cisco in
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-10-10
Published