CVE-2014-3382: SQL Injection
The SQLNet inspection engine in Cisco ASA Software 7.2 before 7.2(5.13), 8.2 before 8.2(5.50), 8.3 before 8.3(2.42), 8.4 before 8.4(7.15), 8.5 before 8.5(1.21), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.5), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via crafted SQL REDIRECT packets, aka Bug ID CSCum46027.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3382?
CVE-2014-3382 has a high severity rating due to its potential to cause a denial of service.
How do I fix CVE-2014-3382?
To mitigate CVE-2014-3382, upgrade Cisco ASA Software to a version that is 7.2(5.13), 8.2(5.50), 8.3(2.42), 8.4(7.15), 8.5(1.21), 8.6(1.14), 8.7(1.13), 9.0(4.5), or 9.1(5.1) or later.
Which versions of Cisco ASA Software are affected by CVE-2014-3382?
CVE-2014-3382 affects multiple versions including 7.2, 8.2 up to 8.2(5.41), 8.3, 8.4, 8.5, 8.6, 8.7, and 9.0, 9.1 before their respective fixed releases.
Is CVE-2014-3382 exploitable remotely?
Yes, CVE-2014-3382 can be exploited remotely by attackers to cause service disruption.
What type of vulnerability is CVE-2014-3382?
CVE-2014-3382 is classified as a denial of service vulnerability in the SQL*Net inspection engine of Cisco ASA Software.