CVE-2014-3389
Summary
| CVE | CVE-2014-3389 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-10 10:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The VPN implementation in Cisco ASA Software 7.2 before 7.2(5.15), 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.15), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), 9.2 before 9.2(2.6), and 9.3 before 9.3(1.1) does not properly implement a tunnel filter, which allows remote authenticated users to obtain failover-unit access via crafted packets, aka Bug ID CSCuq28582. |
Risk And Classification
Primary CVSS: v2.0 9 from [email protected]
AV:N/AC:L/Au:S/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Asa | 7.2.5 | All | All | All |
| Application | Cisco | Asa | 7.2.5.10 | All | All | All |
| Application | Cisco | Asa | 8.2.5 | All | All | All |
| Application | Cisco | Asa | 8.2.5.13 | All | All | All |
| Application | Cisco | Asa | 8.2.5.22 | All | All | All |
| Application | Cisco | Asa | 8.2.5.26 | All | All | All |
| Application | Cisco | Asa | 8.2.5.33 | All | All | All |
| Application | Cisco | Asa | 8.2.5.41 | All | All | All |
| Application | Cisco | Asa | 8.2.5.46 | All | All | All |
| Application | Cisco | Asa | 8.2.5.48 | All | All | All |
| Application | Cisco | Asa | 8.2.5.49 | All | All | All |
| Application | Cisco | Asa | 8.3 | All | All | All |
| Application | Cisco | Asa | 8.3.2.25 | All | All | All |
| Application | Cisco | Asa | 8.4 | All | All | All |
| Application | Cisco | Asa | 8.4.1 | All | All | All |
| Application | Cisco | Asa | 8.4.2 | All | All | All |
| Application | Cisco | Asa | 8.4.3 | All | All | All |
| Application | Cisco | Asa | 8.4.4 | All | All | All |
| Application | Cisco | Asa | 8.4.5 | All | All | All |
| Application | Cisco | Asa | 8.4.6 | All | All | All |
| Application | Cisco | Asa | 8.4.7 | All | All | All |
| Application | Cisco | Asa | 8.6 | All | All | All |
| Application | Cisco | Asa | 9.0 | All | All | All |
| Application | Cisco | Asa | 9.1 | All | All | All |
| Application | Cisco | Asa | 9.2 | All | All | All |
| Application | Cisco | Asa | 9.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Vulnerabilities in Cisco ASA Software | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.