Lucene search

K
nvd[email protected]NVD:CVE-2014-3276
HistoryMay 26, 2014 - 12:25 a.m.

CVE-2014-3276

2014-05-2600:25:31
CWE-399
web.nvd.nist.gov
5

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

AI Score

6.3

Confidence

High

EPSS

0.002

Percentile

58.8%

Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service (RADIUS outage) by sourcing these packets from two origins, aka Bug ID CSCuo56780.

Affected configurations

Nvd
Node
ciscoidentity_services_engine_softwareRange1.2
OR
ciscoidentity_services_engine_softwareMatch1.0
OR
ciscoidentity_services_engine_softwareMatch1.1
VendorProductVersionCPE
ciscoidentity_services_engine_software*cpe:2.3:a:cisco:identity_services_engine_software:*:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.0cpe:2.3:a:cisco:identity_services_engine_software:1.0:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1cpe:2.3:a:cisco:identity_services_engine_software:1.1:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

AI Score

6.3

Confidence

High

EPSS

0.002

Percentile

58.8%

Related for NVD:CVE-2014-3276