First published: Wed Sep 10 2014(Updated: )
The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing System on E-Series blade servers allows remote attackers to cause a denial of service (IMC hang) via a crafted SSH packet, aka Bug ID CSCuo69206.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Integrated Management Controller | <=2.2.2 | |
Cisco Unified Computing System E140d | ||
Cisco Unified Computing System E140dp | ||
Cisco Unified Computing System E140s M1 | ||
Cisco Unified Computing System E140s M2 | ||
Cisco Unified Computing System E160d | ||
Cisco Unified Computing System E160dp | ||
Cisco Unified Computing System En120s M2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3348 has been classified as a moderate severity vulnerability.
To fix CVE-2014-3348, upgrade the Cisco Integrated Management Controller to version 2.3.1 or later.
CVE-2014-3348 affects Cisco Unified Computing System E-Series blade servers running versions prior to 2.3.1.
Yes, CVE-2014-3348 allows remote attackers to cause a denial of service by sending crafted SSH packets.
The impact of CVE-2014-3348 is an IMC hang, leading to interruptions in management functionality.