CVE-2014-3576

HIGH

Apache ActiveMQ < 5.11.0 - Unauthenticated Denial of Service via Shutdown Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-3576. PoCs published by shoucheng3.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2014-3576, which is a vulnerability in Apache ActiveMQ. The exploit appears to target the AMQP protocol implementation, specifically focusing on the protocol discriminator and transport layers.

Description

The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.

Exploits (1)

nomisec WORKING POC
by shoucheng3 · poc
https://github.com/shoucheng3/apache__activemq_CVE-2014-3576_5-10-1

This repository contains a proof-of-concept exploit for CVE-2014-3576, which is a vulnerability in Apache ActiveMQ. The exploit appears to target the AMQP protocol implementation, specifically focusing on the protocol discriminator and transport layers.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Apache ActiveMQ 5.10.1
No auth needed
Prerequisites: Network access to the target ActiveMQ instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3330
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/76272
Various Sources mailing-list x_refsource_mlist
http://activemq.2283324.n4.nabble.com/About-CVE-2014-3576-tp4699628.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033898
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/536862/100/0/threaded

Scores

CVSS v3 7.5
EPSS 0.4073
EPSS Percentile 97.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-264
Status published
Products (7)
apache/activemq < 5.10.0
oracle/business_intelligence_publisher 12.2.1.0.0
oracle/fusion_middleware 8.1
oracle/fusion_middleware 9.0
oracle/fusion_middleware 11.1.1.7.4
oracle/fusion_middleware 12.1.3.0.0
org.apache.activemq/activemq-client 0 - 5.11.0Maven
Published Aug 14, 2015
Tracked Since Feb 18, 2026