Lucene search

K
cveCiscoCVE-2014-3399
HistoryOct 07, 2014 - 10:55 a.m.

CVE-2014-3399

2014-10-0710:55:04
CWE-94
cisco
web.nvd.nist.gov
40
2
ssl vpn
cisco
asa software
remote user
lua injection
denial of service
cve-2014-3399

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

50.6%

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated users to overwrite arbitrary RAMFS cache files or inject Lua programs, and consequently cause a denial of service (portal outage or system reload), via crafted HTTP requests, aka Bug ID CSCup54208.

Affected configurations

Nvd
Node
ciscoadaptive_security_appliance_softwareRange9.2\(2.4\)
VendorProductVersionCPE
ciscoadaptive_security_appliance_software*cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*

Social References

More

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

50.6%

Related for CVE-2014-3399