CVE-2014-3383: High severity cisco asa software vulnerability
Published Oct 10, 2014
·Updated
The IKE implementation in the VPN component in Cisco ASA Software 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via crafted UDP packets, aka Bug ID CSCul36176.
Affected Software
2 affected components
Cisco ASA=9.1
Cisco ASA=9.1.5
Event History
Oct 10, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3383?
CVE-2014-3383 is rated as a high severity vulnerability that allows remote attackers to cause a denial of service.
2
How do I fix CVE-2014-3383?
To fix CVE-2014-3383, upgrade to Cisco ASA Software version 9.1(5.1) or later.
3
What impact does CVE-2014-3383 have on Cisco ASA devices?
CVE-2014-3383 can lead to device reloads due to crafted UDP packets, resulting in a denial of service.
4
Which versions of Cisco ASA are affected by CVE-2014-3383?
Cisco ASA Software versions 9.1 and versions prior to 9.1(5.1) are affected by CVE-2014-3383.
5
Is CVE-2014-3383 exploitable remotely?
Yes, CVE-2014-3383 is exploitable remotely by attackers sending crafted UDP packets.