ID

VAR-201408-0154


CVE

CVE-2014-3330


TITLE

Cisco Nexus 9000 Series Switches Security Bypass Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2014-04850 // CNNVD: CNNVD-201408-103

DESCRIPTION

Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers to bypass intended access restrictions via a flood of packets matching a policy that contains the log keyword, aka Bug ID CSCuo02489. The Cisco Nexus Series switches are data center switches. Adopt the Cisco Nexus OS operating system. A security bypass vulnerability exists in Cisco Nexus 9000 Series Switches that allows an attacker to exploit the vulnerability to bypass an access control list and perform unauthorized operations. This issue is being tracked by Cisco Bug ID CSCuo02489

Trust: 2.52

sources: NVD: CVE-2014-3330 // JVNDB: JVNDB-2014-003734 // CNVD: CNVD-2014-04850 // BID: 69057 // VULHUB: VHN-71270

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-04850

AFFECTED PRODUCTS

vendor:ciscomodel:nx-osscope:eqversion:6.1\(2\)i2\(1\)

Trust: 1.6

vendor:ciscomodel:nexus 9000scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:nexus 9000 seriesscope: - version: -

Trust: 0.8

vendor:ciscomodel:nx-osscope:eqversion:6.1(2)i2(1)

Trust: 0.8

vendor:ciscomodel:nexusscope:eqversion:9000

Trust: 0.6

vendor:ciscomodel:nx-os softwarescope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2014-04850 // BID: 69057 // JVNDB: JVNDB-2014-003734 // CNNVD: CNNVD-201408-103 // NVD: CVE-2014-3330

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3330
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-3330
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-04850
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201408-103
value: MEDIUM

Trust: 0.6

VULHUB: VHN-71270
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-3330
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-04850
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-71270
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-04850 // VULHUB: VHN-71270 // JVNDB: JVNDB-2014-003734 // CNNVD: CNNVD-201408-103 // NVD: CVE-2014-3330

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-71270 // JVNDB: JVNDB-2014-003734 // NVD: CVE-2014-3330

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201408-103

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201408-103

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-003734

PATCH

title:Cisco Nexus 9000 Series Switches Access List Bypass Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3330

Trust: 0.8

title:35181url:http://tools.cisco.com/security/center/viewAlert.x?alertId=35181

Trust: 0.8

title:Patch for Cisco Nexus 9000 Series Switches Security Bypass Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/48415

Trust: 0.6

sources: CNVD: CNVD-2014-04850 // JVNDB: JVNDB-2014-003734

EXTERNAL IDS

db:NVDid:CVE-2014-3330

Trust: 3.4

db:BIDid:69057

Trust: 2.6

db:SECTRACKid:1030676

Trust: 1.1

db:JVNDBid:JVNDB-2014-003734

Trust: 0.8

db:CNNVDid:CNNVD-201408-103

Trust: 0.7

db:CNVDid:CNVD-2014-04850

Trust: 0.6

db:VULHUBid:VHN-71270

Trust: 0.1

sources: CNVD: CNVD-2014-04850 // VULHUB: VHN-71270 // BID: 69057 // JVNDB: JVNDB-2014-003734 // CNNVD: CNNVD-201408-103 // NVD: CVE-2014-3330

REFERENCES

url:http://www.securityfocus.com/bid/69057

Trust: 2.3

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-3330

Trust: 2.0

url:http://tools.cisco.com/security/center/viewalert.x?alertid=35181

Trust: 1.7

url:http://www.securitytracker.com/id/1030676

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/95122

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3330

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-3330

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2014-04850 // VULHUB: VHN-71270 // BID: 69057 // JVNDB: JVNDB-2014-003734 // CNNVD: CNNVD-201408-103 // NVD: CVE-2014-3330

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 69057

SOURCES

db:CNVDid:CNVD-2014-04850
db:VULHUBid:VHN-71270
db:BIDid:69057
db:JVNDBid:JVNDB-2014-003734
db:CNNVDid:CNNVD-201408-103
db:NVDid:CVE-2014-3330

LAST UPDATE DATE

2024-11-23T22:42:33.038000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-04850date:2014-08-08T00:00:00
db:VULHUBid:VHN-71270date:2017-08-29T00:00:00
db:BIDid:69057date:2014-08-05T00:00:00
db:JVNDBid:JVNDB-2014-003734date:2014-08-13T00:00:00
db:CNNVDid:CNNVD-201408-103date:2014-08-12T00:00:00
db:NVDid:CVE-2014-3330date:2024-11-21T02:07:52.823

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-04850date:2014-08-08T00:00:00
db:VULHUBid:VHN-71270date:2014-08-11T00:00:00
db:BIDid:69057date:2014-08-05T00:00:00
db:JVNDBid:JVNDB-2014-003734date:2014-08-13T00:00:00
db:CNNVDid:CNNVD-201408-103date:2014-08-08T00:00:00
db:NVDid:CVE-2014-3330date:2014-08-11T22:55:04.663