4.3
CVSSv2

CVE-2014-3331

Published: 20/08/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11.0, 12.0, 12.1, 12.2, 14.0, 15.0, 16.x up to and including 16.1.2, and 17.0 allows remote malicious users to cause a denial of service (process crash) via a crafted TCP packet, aka Bug ID CSCuo21914.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco asr 5000 series software 14.0

cisco asr 5000 series software 15.0

cisco asr 5000 series software 11.0

cisco asr 5000 series software 12.0

cisco asr 5000 series software 17.0.0

cisco asr 5000 series software 16.1.0

cisco asr 5000 series software 16.1.1

cisco asr 5000 series software 16.1.2

cisco asr 5000 series software 12.1

cisco asr 5000 series software 12.2

Vendor Advisories

A vulnerability in the Session Manager software of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to cause the Session Manager to crash The issue is due to insufficient validation of received TCP packets An attacker could exploit this issue by sending a crafted TCP packet An exploit could allow the attac ...