CVE-2014-3402
Summary
| CVE | CVE-2014-3402 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-10 10:55:00 UTC |
| Updated | 2014-10-15 13:05:00 UTC |
| Description | The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug ID CSCuq39550. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Intrusion Prevention System | 7.0 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0(1)e3 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0(2)e3 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0(2)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0(3)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0(4)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0(5a)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0(6)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0(7)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(1\)e3 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(2\)e3 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(2\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(3\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(4\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(5a\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(6\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(7\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(1\)e3 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(2\)e3 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(2\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(3\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(4\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(5a\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(6\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(7\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | All | All | All | All |
| Application | Cisco | Intrusion Prevention System | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| tools.cisco.com/security/center/viewAlert.x | CONFIRM | tools.cisco.com | Vendor Advisory |
| 20141007 Cisco Intrusion Prevention System MainApp Denial of Service Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.