CVE-2014-3331: Input Validation
The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11.0, 12.0, 12.1, 12.2, 14.0, 15.0, 16.x through 16.1.2, and 17.0 allows remote attackers to cause a denial of service (process crash) via a crafted TCP packet, aka Bug ID CSCuo21914.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3331?
CVE-2014-3331 has been classified as a moderate severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2014-3331?
To mitigate CVE-2014-3331, it's recommended to update the Cisco ASR 5000 Series Software to a patched version.
What systems are affected by CVE-2014-3331?
CVE-2014-3331 affects Cisco ASR 5000 Series Software versions 11.0, 12.0, 12.1, 12.2, 14.0, 15.0, and 16.x up to 16.1.2, and 17.0.
What type of attack does CVE-2014-3331 allow?
CVE-2014-3331 allows remote attackers to trigger a denial of service by sending crafted TCP packets.
Is CVE-2014-3331 still exploitable?
The exploitability of CVE-2014-3331 depends on the deployment of vulnerable versions in production environments without patches applied.