MEDIUM · 5.4

CVE-2014-3347

Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN pho...

Vulnerability Description

Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid state of the hardware encryption module, aka Bug ID CSCul77897.

CVSS Score

5.4

MEDIUM

AV:N/AC:H/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoIos15.1\(4\)m2
Cisco1801 Integrated Service Router-
Cisco1802 Integrated Service Router-
Cisco1803 Integrated Service Router-
Cisco1811 Integrated Service Router-
Cisco1812 Integrated Service Router-
Cisco1841 Integrated Service Router-
Cisco1861 Integrated Service Router-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-3347?

CVE-2014-3347 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN pho...

How severe is CVE-2014-3347?

CVE-2014-3347 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-3347?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios, Cisco 1801 Integrated Service Router, Cisco 1802 Integrated Service Router, Cisco 1803 Integrated Service Router, Cisco 1811 Integrated Service Router.