ID

VAR-201404-0560


CVE

CVE-2014-2182


TITLE

Cisco Adaptive Security Appliance Service disruption in software (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-002265

DESCRIPTION

Cisco Adaptive Security Appliance (ASA) Software, when DHCPv6 replay is configured, allows remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 packet, aka Bug ID CSCun45520. An attacker can exploit this issue to cause the affected device to reload, denying service to legitimate users. This issue is tracked by Cisco Bug ID CSCun45520

Trust: 1.98

sources: NVD: CVE-2014-2182 // JVNDB: JVNDB-2014-002265 // BID: 67100 // VULHUB: VHN-70121

AFFECTED PRODUCTS

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion: -

Trust: 1.6

vendor:ciscomodel:adaptive security appliancescope: - version: -

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:lteversion:9.1.5

Trust: 0.8

sources: JVNDB: JVNDB-2014-002265 // CNNVD: CNNVD-201404-566 // NVD: CVE-2014-2182

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-2182
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-2182
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201404-566
value: MEDIUM

Trust: 0.6

VULHUB: VHN-70121
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-2182
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-70121
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-70121 // JVNDB: JVNDB-2014-002265 // CNNVD: CNNVD-201404-566 // NVD: CVE-2014-2182

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-70121 // JVNDB: JVNDB-2014-002265 // NVD: CVE-2014-2182

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201404-566

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201404-566

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-002265

PATCH

title:Cisco ASA DHCPv6 Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2182

Trust: 0.8

title:33980url:http://tools.cisco.com/security/center/viewAlert.x?alertId=33980

Trust: 0.8

sources: JVNDB: JVNDB-2014-002265

EXTERNAL IDS

db:NVDid:CVE-2014-2182

Trust: 2.8

db:JVNDBid:JVNDB-2014-002265

Trust: 0.8

db:CNNVDid:CNNVD-201404-566

Trust: 0.7

db:CISCOid:20140428 CISCO ASA DHCPV6 DENIAL OF SERVICE VULNERABILITY

Trust: 0.6

db:BIDid:67100

Trust: 0.4

db:VULHUBid:VHN-70121

Trust: 0.1

sources: VULHUB: VHN-70121 // BID: 67100 // JVNDB: JVNDB-2014-002265 // CNNVD: CNNVD-201404-566 // NVD: CVE-2014-2182

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-2182

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-2182

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-2182

Trust: 0.8

url:www.cisco.com

Trust: 0.3

sources: VULHUB: VHN-70121 // BID: 67100 // JVNDB: JVNDB-2014-002265 // CNNVD: CNNVD-201404-566 // NVD: CVE-2014-2182

CREDITS

Cisco

Trust: 0.3

sources: BID: 67100

SOURCES

db:VULHUBid:VHN-70121
db:BIDid:67100
db:JVNDBid:JVNDB-2014-002265
db:CNNVDid:CNNVD-201404-566
db:NVDid:CVE-2014-2182

LAST UPDATE DATE

2024-11-23T22:49:31.737000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-70121date:2014-04-29T00:00:00
db:BIDid:67100date:2014-05-02T00:50:00
db:JVNDBid:JVNDB-2014-002265date:2014-04-30T00:00:00
db:CNNVDid:CNNVD-201404-566date:2014-04-30T00:00:00
db:NVDid:CVE-2014-2182date:2024-11-21T02:05:48.547

SOURCES RELEASE DATE

db:VULHUBid:VHN-70121date:2014-04-29T00:00:00
db:BIDid:67100date:2014-04-28T00:00:00
db:JVNDBid:JVNDB-2014-002265date:2014-04-30T00:00:00
db:CNNVDid:CNNVD-201404-566date:2014-04-30T00:00:00
db:NVDid:CVE-2014-2182date:2014-04-29T10:37:03.997