cbcvebase.
CVE-2014-3402
published 2014-10-10

CVE-2014-3402: The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System…

PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.34%
68.1th percentile
The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug ID CSCuq39550.

Affected

10 ranges
VendorProductVersion rangeFixed in
ciscointrusion_prevention_system<= 7.0\(8\)e4
ciscointrusion_prevention_system
ciscointrusion_prevention_system
ciscointrusion_prevention_system
ciscointrusion_prevention_system
ciscointrusion_prevention_system
ciscointrusion_prevention_system
ciscointrusion_prevention_system
ciscointrusion_prevention_system
ciscointrusion_prevention_system

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.