Lucene search

K
nvd[email protected]NVD:CVE-2014-3399
HistoryOct 07, 2014 - 10:55 a.m.

CVE-2014-3399

2014-10-0710:55:04
CWE-94
web.nvd.nist.gov
4

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

50.6%

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated users to overwrite arbitrary RAMFS cache files or inject Lua programs, and consequently cause a denial of service (portal outage or system reload), via crafted HTTP requests, aka Bug ID CSCup54208.

Affected configurations

Nvd
Node
ciscoadaptive_security_appliance_softwareRange9.2\(2.4\)
VendorProductVersionCPE
ciscoadaptive_security_appliance_software*cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

50.6%

Related for NVD:CVE-2014-3399