5
CVSSv2

CVE-2014-3407

Published: 28/11/2014 Updated: 02/06/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and previous versions does not properly allocate memory blocks during HTTP packet handling, which allows remote malicious users to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCuq68888.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive security appliance software

Vendor Advisories

A vulnerability in the SSL VPN feature of Cisco ASA Software could allow an unauthenticated, remote attacker to cause the exhaustion of available memory, which could lead to system instability and availability issues on the SSL VPN services The vulnerability is due to improper implementation of memory block allocation when processing crafted HTTP ...