CVE-2014-3276
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service (RADIUS outage) by sourcing these packets from two origins, aka Bug ID CSCuo56780.
Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) y anteriores no maneja debidamente condiciones de bloqueo durante la recepción de paquetes de contabilidad RADIUS manipulados de múltiples dispositivos NAS, lo que permite a usuarios remotos autenticados causar una denegación de servicio (RADIUS outage) mediante la obtención de estos paquetes de dos origines, también conocido como Bug ID CSCuo56780.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-07 CVE Reserved
- 2014-05-23 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1030274 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3276 | 2016-09-07 | |
http://tools.cisco.com/security/center/viewAlert.x?alertId=34329 | 2016-09-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Identity Services Engine Software Search vendor "Cisco" for product "Identity Services Engine Software" | <= 1.2 Search vendor "Cisco" for product "Identity Services Engine Software" and version " <= 1.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Software Search vendor "Cisco" for product "Identity Services Engine Software" | 1.0 Search vendor "Cisco" for product "Identity Services Engine Software" and version "1.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Software Search vendor "Cisco" for product "Identity Services Engine Software" | 1.1 Search vendor "Cisco" for product "Identity Services Engine Software" and version "1.1" | - |
Affected
|