ID

VAR-201408-0168


CVE

CVE-2014-3347


TITLE

Cisco 1800 ISR Run on device Cisco IOS Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-003988

DESCRIPTION

Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid state of the hardware encryption module, aka Bug ID CSCul77897. Cisco 1800 Series are prone to a remote denial-of-service vulnerability. Attackers can exploit this issue to cause the device unresponsive, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCul77897. Cisco IOS on Cisco 1800 ISR is a set of operating systems run by Cisco 1800 ISR series routers

Trust: 1.98

sources: NVD: CVE-2014-3347 // JVNDB: JVNDB-2014-003988 // BID: 69439 // VULHUB: VHN-71287

AFFECTED PRODUCTS

vendor:ciscomodel:iosscope:eqversion:15.1\(4\)m2

Trust: 1.6

vendor:ciscomodel:1801 integrated service routerscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:1812 integrated service routerscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:1841 integrated service routerscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:1861 integrated service routerscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:1802 integrated service routerscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:1803 integrated service routerscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:1811 integrated service routerscope:eqversion: -

Trust: 1.0

vendor:ciscomodel:1801 integrated service routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:1802 integrated service routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:1803 integrated service routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:1811 integrated service routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:1812 integrated service routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:1841 integrated service routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:1861 integrated service routerscope: - version: -

Trust: 0.8

vendor:ciscomodel:iosscope:lteversion:15.1(4)m2

Trust: 0.8

vendor:ciscomodel:ios 15.1mscope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 15.1 m4scope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 15.1 m3ascope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 15.1 m3scope: - version: -

Trust: 0.3

vendor:ciscomodel:ios 15.1 m2scope: - version: -

Trust: 0.3

sources: BID: 69439 // JVNDB: JVNDB-2014-003988 // CNNVD: CNNVD-201408-438 // NVD: CVE-2014-3347

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3347
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-3347
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201408-438
value: MEDIUM

Trust: 0.6

VULHUB: VHN-71287
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-3347
severity: MEDIUM
baseScore: 5.4
vectorString: AV:N/AC:H/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-71287
severity: MEDIUM
baseScore: 5.4
vectorString: AV:N/AC:H/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-71287 // JVNDB: JVNDB-2014-003988 // CNNVD: CNNVD-201408-438 // NVD: CVE-2014-3347

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-71287 // JVNDB: JVNDB-2014-003988 // NVD: CVE-2014-3347

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201408-438

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201408-438

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-003988

PATCH

title:Cisco 1800 Series ISR ISDN Basic Rate Interface Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3347

Trust: 0.8

title:35453url:http://tools.cisco.com/security/center/viewAlert.x?alertId=35453

Trust: 0.8

sources: JVNDB: JVNDB-2014-003988

EXTERNAL IDS

db:NVDid:CVE-2014-3347

Trust: 2.8

db:BIDid:69439

Trust: 1.4

db:SECTRACKid:1030772

Trust: 1.1

db:JVNDBid:JVNDB-2014-003988

Trust: 0.8

db:CNNVDid:CNNVD-201408-438

Trust: 0.7

db:VULHUBid:VHN-71287

Trust: 0.1

sources: VULHUB: VHN-71287 // BID: 69439 // JVNDB: JVNDB-2014-003988 // CNNVD: CNNVD-201408-438 // NVD: CVE-2014-3347

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-3347

Trust: 1.7

url:http://tools.cisco.com/security/center/viewalert.x?alertid=35453

Trust: 1.7

url:http://www.securityfocus.com/bid/69439

Trust: 1.1

url:http://www.securitytracker.com/id/1030772

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/95558

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3347

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-3347

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-71287 // BID: 69439 // JVNDB: JVNDB-2014-003988 // CNNVD: CNNVD-201408-438 // NVD: CVE-2014-3347

CREDITS

Cisco

Trust: 0.3

sources: BID: 69439

SOURCES

db:VULHUBid:VHN-71287
db:BIDid:69439
db:JVNDBid:JVNDB-2014-003988
db:CNNVDid:CNNVD-201408-438
db:NVDid:CVE-2014-3347

LAST UPDATE DATE

2024-11-23T22:02:03.673000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-71287date:2017-08-29T00:00:00
db:BIDid:69439date:2014-09-01T00:13:00
db:JVNDBid:JVNDB-2014-003988date:2014-09-01T00:00:00
db:CNNVDid:CNNVD-201408-438date:2014-08-29T00:00:00
db:NVDid:CVE-2014-3347date:2024-11-21T02:07:54.767

SOURCES RELEASE DATE

db:VULHUBid:VHN-71287date:2014-08-28T00:00:00
db:BIDid:69439date:2014-08-27T00:00:00
db:JVNDBid:JVNDB-2014-003988date:2014-09-01T00:00:00
db:CNNVDid:CNNVD-201408-438date:2014-08-29T00:00:00
db:NVDid:CVE-2014-3347date:2014-08-28T23:55:05.513