CVE-2014-3407

Cisco Adaptive Security Appliance Software < 9.3(2) - Denial of Service via SSL VPN HTTP Packet Handling

Title source: llm
STIX 2.1

Description

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCuq68888.

References (2)

Core 2
Core References
Broken Link, Vendor Advisory vendor-advisory x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3407

Scores

EPSS 0.0170
EPSS Percentile 74.3%

Details

CWE
CWE-400
Status published
Products (1)
cisco/adaptive_security_appliance_software < 9.3\(2\)
Published Nov 28, 2014
Tracked Since Feb 18, 2026