CVE-2014-3402
Summary
| CVE | CVE-2014-3402 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-10 10:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug ID CSCuq39550. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Intrusion Prevention System | 7.0 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(1\)e3 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(2\)e3 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(2\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(3\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(4\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(5a\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(6\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | 7.0\(7\)e4 | All | All | All |
| Application | Cisco | Intrusion Prevention System | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| tools.cisco.com/security/center/viewAlert.x | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3402 | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.