CVE-2014-3406
published 2014-10-19CVE-2014-3406: Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of…
PriorityP429high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
0.89%
55.1th percentile
Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | intrusion_prevention_system | <= 7.1\(7\)e4 | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-23fc-p3ph-rj82: Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7
ghsa_unreviewed·2022-05-17
CVE-2014-3406 [HIGH] CWE-362 GHSA-23fc-p3ph-rj82: Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7
Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085.
Cisco
Cisco Intrusion Prevention System IP Logging Denial of Service Vulnerability
vendor_cisco·2014-10-14·CVSS 7.1
CVE-2014-3406 [HIGH] CWE-362 Cisco Intrusion Prevention System IP Logging Denial of Service Vulnerability
Cisco Intrusion Prevention System IP Logging Denial of Service Vulnerability
A vulnerability in the IP logging feature of Cisco Intrusion Prevention System (IPS) Software could allow
an unauthenticated, remote attacker to cause a reload of the affected
system.
The vulnerability is due to a race condition when
writing the IP logging file. An attacker could exploit this
vulnerability by sending traffic through the sensor that would hit the rule configured with the IP logging feature.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, the IP logging feature must be configured on a targeted device, and the attacker may need to acquire additional information about whether this feature is enabled. In addition, the attacke
No detection rules found.
No public exploits indexed.
2014-10-19
Published