CVE-2014-2129: Input Validation
The SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.48), 8.4 before 8.4(6.5), 9.0 before 9.0(3.1), and 9.1 before 9.1(2.5) allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted SIP packets, aka Bug ID CSCuh44052.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2129?
CVE-2014-2129 has been classified as a medium severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2014-2129?
To mitigate CVE-2014-2129, upgrade your Cisco Adaptive Security Appliance software to the versions specified by Cisco in the advisory.
What systems are affected by CVE-2014-2129?
CVE-2014-2129 affects Cisco Adaptive Security Appliance software versions 8.2, 8.4, 9.0, and 9.1 prior to their respective patch releases.
What type of attack does CVE-2014-2129 enable?
CVE-2014-2129 enables remote attackers to execute denial of service attacks through crafted SIP packets.
When was CVE-2014-2129 disclosed?
CVE-2014-2129 was disclosed on April 9, 2014, as part of a security advisory from Cisco.