ID

VAR-201410-1004


CVE

CVE-2014-3385


TITLE

Cisco ASA Software ASDM Functional Health and Performance Monitoring Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-004659

DESCRIPTION

Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8.3 before 8.3(2.42), 8.4 before 8.4(7.11), 8.5 before 8.5(1.19), 8.6 before 8.6(1.13), 8.7 before 8.7(1.11), 9.0 before 9.0(4.8), and 9.1 before 9.1(4.5) allows remote attackers to cause a denial of service (device reload) via TCP traffic that triggers many half-open connections at the same time, aka Bug ID CSCum00556. Cisco Adaptive Security Appliance (ASA) Software is prone to a denial-of-service vulnerability. An attacker can exploit this issue to cause the affected device to reload, denying service to legitimate users. This issue is tracked by Cisco Bug ID CSCum00556. Cisco ASA is a set of firewall equipment of Cisco (Cisco). The device also includes IPS (Intrusion Prevention System), SSL VPN, IPSec VPN, antispam, and more. The following releases are affected: Cisco ASA Software 8.3 prior to 8.3(2.42), 8.4 prior to 8.4(7.11), 8.5 prior to 8.5(1.19), 8.6 prior to 8.6(1.13), 8.7 prior to 8.7(1.11), 9.0( 4.8) before 9.0, 9.1(4.5) before 9.1

Trust: 1.98

sources: NVD: CVE-2014-3385 // JVNDB: JVNDB-2014-004659 // BID: 70298 // VULHUB: VHN-71325

AFFECTED PRODUCTS

vendor:ciscomodel:asascope:eqversion:8.7

Trust: 1.6

vendor:ciscomodel:asascope:eqversion:8.4.7

Trust: 1.6

vendor:ciscomodel:asascope:eqversion:8.6

Trust: 1.6

vendor:ciscomodel:asascope:eqversion:9.0

Trust: 1.6

vendor:ciscomodel:asascope:eqversion:8.5

Trust: 1.6

vendor:ciscomodel:asascope:eqversion:8.4.4

Trust: 1.6

vendor:ciscomodel:asascope:eqversion:8.4.5

Trust: 1.6

vendor:ciscomodel:asascope:eqversion:8.5.1.6

Trust: 1.6

vendor:ciscomodel:asascope:eqversion:8.4.6

Trust: 1.6

vendor:ciscomodel:asascope:eqversion:9.1

Trust: 1.6

vendor:ciscomodel:asascope:eqversion:8.4.3

Trust: 1.0

vendor:ciscomodel:asascope:eqversion:8.4.1

Trust: 1.0

vendor:ciscomodel:asascope:eqversion:8.4

Trust: 1.0

vendor:ciscomodel:asascope:eqversion:8.3.2.25

Trust: 1.0

vendor:ciscomodel:asascope:eqversion:8.4.2

Trust: 1.0

vendor:ciscomodel:asascope:eqversion:8.3

Trust: 1.0

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.7(1.11)

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:8.3

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:8.5

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.6(1.13)

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:9.0(4.8)

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:9.1(4.5)

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:9.1

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.4(7.11)

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:8.4

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.3(2.42)

Trust: 0.8

vendor:ciscomodel:adaptive security appliancescope:eqversion:(asa)

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.5(1.19)

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:9.0

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:8.6

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:ltversion:8.7

Trust: 0.8

sources: JVNDB: JVNDB-2014-004659 // CNNVD: CNNVD-201410-208 // NVD: CVE-2014-3385

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3385
value: HIGH

Trust: 1.0

NVD: CVE-2014-3385
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201410-208
value: HIGH

Trust: 0.6

VULHUB: VHN-71325
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-3385
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-71325
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-71325 // JVNDB: JVNDB-2014-004659 // CNNVD: CNNVD-201410-208 // NVD: CVE-2014-3385

PROBLEMTYPE DATA

problemtype:CWE-362

Trust: 1.9

sources: VULHUB: VHN-71325 // JVNDB: JVNDB-2014-004659 // NVD: CVE-2014-3385

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201410-208

TYPE

competitive condition

Trust: 0.6

sources: CNNVD: CNNVD-201410-208

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-004659

PATCH

title:cisco-sa-20141008-asaurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141008-asa

Trust: 0.8

title:35908url:http://tools.cisco.com/security/center/viewAlert.x?alertId=35908

Trust: 0.8

title:cisco-sa-20141008-asaurl:http://www.cisco.com/cisco/web/support/JP/112/1126/1126286_cisco-sa-20141008-asa-j.html

Trust: 0.8

sources: JVNDB: JVNDB-2014-004659

EXTERNAL IDS

db:NVDid:CVE-2014-3385

Trust: 2.8

db:JVNDBid:JVNDB-2014-004659

Trust: 0.8

db:CNNVDid:CNNVD-201410-208

Trust: 0.7

db:BIDid:70298

Trust: 0.4

db:VULHUBid:VHN-71325

Trust: 0.1

sources: VULHUB: VHN-71325 // BID: 70298 // JVNDB: JVNDB-2014-004659 // CNNVD: CNNVD-201410-208 // NVD: CVE-2014-3385

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20141008-asa

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3385

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-3385

Trust: 0.8

url:http://tools.cisco.com/security/center/viewalert.x?alertid=35908

Trust: 0.3

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-71325 // BID: 70298 // JVNDB: JVNDB-2014-004659 // CNNVD: CNNVD-201410-208 // NVD: CVE-2014-3385

CREDITS

Cisco

Trust: 0.3

sources: BID: 70298

SOURCES

db:VULHUBid:VHN-71325
db:BIDid:70298
db:JVNDBid:JVNDB-2014-004659
db:CNNVDid:CNNVD-201410-208
db:NVDid:CVE-2014-3385

LAST UPDATE DATE

2025-04-13T23:23:52.426000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-71325date:2014-10-12T00:00:00
db:BIDid:70298date:2014-10-08T00:00:00
db:JVNDBid:JVNDB-2014-004659date:2014-10-14T00:00:00
db:CNNVDid:CNNVD-201410-208date:2014-10-29T00:00:00
db:NVDid:CVE-2014-3385date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-71325date:2014-10-10T00:00:00
db:BIDid:70298date:2014-10-08T00:00:00
db:JVNDBid:JVNDB-2014-004659date:2014-10-14T00:00:00
db:CNNVDid:CNNVD-201410-208date:2014-10-29T00:00:00
db:NVDid:CVE-2014-3385date:2014-10-10T10:55:06.290