Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco Intrusion Prevention System IP Logging Denial of Service Vulnerability

Cisco-SA-20141014-CVE-2014-3406 · Medium · Published · Updated

A vulnerability in the IP logging feature of Cisco Intrusion Prevention System (IPS) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to a race condition when writing the IP logging file. An attacker could exploit this vulnerability by sending traffic through the sensor that would hit the rule configured with the IP logging feature. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, the IP logging feature must be configured on a targeted device, and the attacker may need to acquire additional information about whether this feature is enabled. In addition, the attacker may need access to trusted, internal networks in which the targeted device may reside to send traffic to hit the rule configured with the IP logging feature. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Cisco advisory · CSAF JSON

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to have network access.

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2014-3406
Cisco Bug IDsCSCud82085
CVSS ScoreBase 5.4
Base 5.4 AV:N/AC:H/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C
Product Names From Source
Cisco Intrusion Prevention System (IPS), Intrusion Prevention System (IPS)

Related Products

Product CVE Evidence
Intrusion Prevention System (IPS) CVE-2014-3406 Cisco OpenVuln
Cisco Intrusion Prevention System (IPS) CVE-2014-3406 Cisco OpenVuln