CVE-2014-3328: Medium severity cisco unified presence vulnerability
Published Jul 26, 2014
·Updated
The Intercluster Sync Agent Service in Cisco Unified Presence Server allows remote attackers to cause a denial of service via a TCP SYN flood, aka Bug ID CSCun34125.
Affected Software
1 affected component
Cisco Unified Presence Server
Event History
Jul 26, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3328?
CVE-2014-3328 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-3328?
To mitigate CVE-2014-3328, you should implement network-level protections against TCP SYN floods such as rate limiting.
3
What systems are affected by CVE-2014-3328?
CVE-2014-3328 affects Cisco Unified Presence Server systems.
4
What type of attack does CVE-2014-3328 facilitate?
CVE-2014-3328 allows for remote attackers to execute a denial of service attack via a TCP SYN flood.
5
Is there a patch available for CVE-2014-3328?
There is no specific patch for CVE-2014-3328, but recommended security functions should be applied.