Lucene search

K
cveCiscoCVE-2014-3404
HistoryOct 10, 2014 - 1:55 a.m.

CVE-2014-3404

2014-10-1001:55:09
CWE-310
cisco
web.nvd.nist.gov
28
autonomic networking infrastructure
cisco ios xe
certificates validation
remote attackers
cve-2014-3404

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

49.4%

The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to trigger acceptance of an invalid message via crafted messages, aka Bug ID CSCuq22677.

Affected configurations

Nvd
Node
ciscoios_xeMatch-
VendorProductVersionCPE
ciscoios_xe-cpe:2.3:o:cisco:ios_xe:-:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

49.4%

Related for CVE-2014-3404