HIGH · 7.6

CVE-2014-3261

Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, N...

Vulnerability Description

Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2 before 5.2(3a) on Nexus 7000 devices, and CG-OS CG4 before CG4(2) on Connected 1000 Connected Grid Routers allows remote SMTP servers to execute arbitrary code via a crafted reply, aka Bug IDs CSCtk00695, CSCts56633, CSCts56632, CSCts56628, CSCug14405, and CSCuf61322.

CVSS Score

7.6

HIGH

AV:N/AC:H/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoUnified Computing System 6120Xp Fabric Interconnect-
CiscoUnified Computing System 6140Xp Fabric Interconnect-
CiscoUnified Computing System 6248Up Fabric Interconnect-
CiscoUnified Computing System 6296Up Fabric Interconnect-
CiscoUnified Computing System Infrastructure And Unified Computing System Software1.4\(1j\)
CiscoCg-Oscg4
CiscoCgr 1120-
CiscoCgr 1240-
CiscoNx-Os5.2
CiscoNexus 7000-
CiscoNexus 7000 10-Slot-
CiscoNexus 7000 18-Slot-
CiscoNexus 7000 9-Slot-
CiscoNexus 3016Q-
CiscoNexus 3048-
CiscoNexus 3064T-
CiscoNexus 3064X-
CiscoNexus 3548-
CiscoNexus 5000-
CiscoNexus 5010-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-3261?

CVE-2014-3261 is a vulnerability with a CVSS score of 7.6 (HIGH). Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, N...

How severe is CVE-2014-3261?

CVE-2014-3261 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-3261?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Computing System 6120Xp Fabric Interconnect, Cisco Unified Computing System 6140Xp Fabric Interconnect, Cisco Unified Computing System 6248Up Fabric Interconnect, Cisco Unified Computing System 6296Up Fabric Interconnect, Cisco Unified Computing System Infrastructure And Unified Computing System Software.