5
CVSSv2

CVE-2014-3402

Published: 10/10/2014 Updated: 15/10/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and previous versions in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote malicious users to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug ID CSCuq39550.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco intrusion prevention system 7.0

cisco intrusion prevention system 7.0\\(1\\)e3

cisco intrusion prevention system 7.0\\(2\\)e4

cisco intrusion prevention system 7.0\\(4\\)e4

cisco intrusion prevention system 7.0\\(5a\\)e4

cisco intrusion prevention system 7.0\\(6\\)e4

cisco intrusion prevention system 7.0\\(7\\)e4

cisco intrusion prevention system

cisco intrusion prevention system 7.0\\(2\\)e3

cisco intrusion prevention system 7.0\\(3\\)e4

Vendor Advisories

A vulnerability in the web framework of Cisco Intrusion Prevention System (IPS) Software could allow an authenticated, remote attacker to cause MainApp to hang intermittently because the authentication manager process creates a denial of service (DoS) condition The vulnerability is due to improper handling of user tokens An attacker could exploi ...