ID

VAR-201410-0063


CVE

CVE-2014-3403


TITLE

Cisco IOS XE of Autonomic Networking Infrastructure Component impersonation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2014-004653

DESCRIPTION

The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to spoof devices via crafted messages, aka Bug ID CSCuq22647. Vendors have confirmed this vulnerability Bug ID CSCuq22647 It is released as.A third party can impersonate the device through a crafted message. Cisco IOS is the interconnected network operating system used on most Cisco system routers and network switches. Cisco IOS XE has a security bypass vulnerability that allows an attacker to bypass certain security restrictions and perform unauthorized operations. Cisco IOS XE Software is prone to a security-bypass vulnerability. This issue is being tracked by Cisco Bug ID CSCuq22647. The vulnerability is caused by the program not validating certificates properly

Trust: 2.52

sources: NVD: CVE-2014-3403 // JVNDB: JVNDB-2014-004653 // CNVD: CNVD-2014-06655 // BID: 70386 // VULHUB: VHN-71343

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-06655

AFFECTED PRODUCTS

vendor:ciscomodel:ios xescope:eqversion: -

Trust: 1.6

vendor:ciscomodel:ios xescope:eqversion:3.13s

Trust: 0.8

vendor:ciscomodel:ios xescope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2014-06655 // JVNDB: JVNDB-2014-004653 // CNNVD: CNNVD-201410-194 // NVD: CVE-2014-3403

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3403
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-3403
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-06655
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201410-194
value: MEDIUM

Trust: 0.6

VULHUB: VHN-71343
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-3403
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-06655
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-71343
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-06655 // VULHUB: VHN-71343 // JVNDB: JVNDB-2014-004653 // CNNVD: CNNVD-201410-194 // NVD: CVE-2014-3403

PROBLEMTYPE DATA

problemtype:CWE-310

Trust: 1.9

sources: VULHUB: VHN-71343 // JVNDB: JVNDB-2014-004653 // NVD: CVE-2014-3403

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201410-194

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-201410-194

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-004653

PATCH

title:Autonomic Networking Infrastructure Certificate Validation Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3403

Trust: 0.8

title:36032url:http://tools.cisco.com/security/center/viewAlert.x?alertId=36032

Trust: 0.8

sources: JVNDB: JVNDB-2014-004653

EXTERNAL IDS

db:NVDid:CVE-2014-3403

Trust: 3.4

db:BIDid:70386

Trust: 1.0

db:JVNDBid:JVNDB-2014-004653

Trust: 0.8

db:CNNVDid:CNNVD-201410-194

Trust: 0.7

db:CNVDid:CNVD-2014-06655

Trust: 0.6

db:VULHUBid:VHN-71343

Trust: 0.1

sources: CNVD: CNVD-2014-06655 // VULHUB: VHN-71343 // BID: 70386 // JVNDB: JVNDB-2014-004653 // CNNVD: CNNVD-201410-194 // NVD: CVE-2014-3403

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-3403

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3403

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-3403

Trust: 0.8

url:http://www.securityfocus.com/bid/70386

Trust: 0.6

url:www.cisco.com

Trust: 0.3

sources: CNVD: CNVD-2014-06655 // VULHUB: VHN-71343 // BID: 70386 // JVNDB: JVNDB-2014-004653 // CNNVD: CNNVD-201410-194 // NVD: CVE-2014-3403

CREDITS

Cisco

Trust: 0.3

sources: BID: 70386

SOURCES

db:CNVDid:CNVD-2014-06655
db:VULHUBid:VHN-71343
db:BIDid:70386
db:JVNDBid:JVNDB-2014-004653
db:CNNVDid:CNNVD-201410-194
db:NVDid:CVE-2014-3403

LAST UPDATE DATE

2024-11-23T22:08:17.283000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-06655date:2014-10-14T00:00:00
db:VULHUBid:VHN-71343date:2014-10-10T00:00:00
db:BIDid:70386date:2014-10-13T00:01:00
db:JVNDBid:JVNDB-2014-004653date:2014-10-14T00:00:00
db:CNNVDid:CNNVD-201410-194date:2014-10-14T00:00:00
db:NVDid:CVE-2014-3403date:2024-11-21T02:08:01.167

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-06655date:2014-10-13T00:00:00
db:VULHUBid:VHN-71343date:2014-10-10T00:00:00
db:BIDid:70386date:2014-10-09T00:00:00
db:JVNDBid:JVNDB-2014-004653date:2014-10-14T00:00:00
db:CNNVDid:CNNVD-201410-194date:2014-10-14T00:00:00
db:NVDid:CVE-2014-3403date:2014-10-10T01:55:09.070