Vulnerability Description
The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing System on E-Series blade servers allows remote attackers to cause a denial of service (IMC hang) via a crafted SSH packet, aka Bug ID CSCuo69206.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Integrated Management Controller | <= 2.2.2 |
| Cisco | Unified Computing System E140D | - |
| Cisco | Unified Computing System E140Dp | - |
| Cisco | Unified Computing System E140S M1 | - |
| Cisco | Unified Computing System E140S M2 | - |
| Cisco | Unified Computing System E160D | - |
| Cisco | Unified Computing System E160Dp | - |
| Cisco | Unified Computing System En120S M2 | - |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3348Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=35588Vendor Advisory
- http://www.securityfocus.com/bid/69652
- http://www.securitytracker.com/id/1030813
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95782
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3348Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=35588Vendor Advisory
- http://www.securityfocus.com/bid/69652
- http://www.securitytracker.com/id/1030813
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95782
FAQ
What is CVE-2014-3348?
CVE-2014-3348 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing System on E-Series blade servers allows remote attackers to cause a denial of service (IMC hang) vi...
How severe is CVE-2014-3348?
CVE-2014-3348 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3348?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Integrated Management Controller, Cisco Unified Computing System E140D, Cisco Unified Computing System E140Dp, Cisco Unified Computing System E140S M1, Cisco Unified Computing System E140S M2.