CVE-2014-3382

Cisco ASA Software 7.2-9.1 - Denial of Service via SQL*Net Inspection Engine

Title source: llm
STIX 2.1

Description

The SQL*Net inspection engine in Cisco ASA Software 7.2 before 7.2(5.13), 8.2 before 8.2(5.50), 8.3 before 8.3(2.42), 8.4 before 8.4(7.15), 8.5 before 8.5(1.21), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.5), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via crafted SQL REDIRECT packets, aka Bug ID CSCum46027.

References (1)

Core 1
Core References

Scores

EPSS 0.0138
EPSS Percentile 69.2%

Details

CWE
CWE-89
Status published
Products (27)
cisco/asa 7.2.5
cisco/asa 7.2.5.10
cisco/asa 8.2.5
cisco/asa 8.2.5.13
cisco/asa 8.2.5.22
cisco/asa 8.2.5.26
cisco/asa 8.2.5.33
cisco/asa 8.2.5.41
cisco/asa 8.2.5.46
cisco/asa 8.2.5.48
... and 17 more
Published Oct 10, 2014
Tracked Since Feb 18, 2026