CVE-2014-3386: High severity cisco asa software vulnerability
The GPRS Tunneling Protocol (GTP) inspection engine in Cisco ASA Software 8.2 before 8.2(5.51), 8.4 before 8.4(7.15), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted series of GTP packets, aka Bug ID CSCum56399.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3386?
CVE-2014-3386 is classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2014-3386?
To fix CVE-2014-3386, upgrade your Cisco ASA Software to a version that is not vulnerable, specifically 8.2(5.51), 8.4(7.15) or higher, 8.7(1.13) or higher, 9.0(4.8) or higher, or 9.1(5.1) or higher.
Which Cisco ASA versions are affected by CVE-2014-3386?
CVE-2014-3386 affects Cisco ASA Software versions 8.2 before 8.2(5.51), 8.4 before 8.4(7.15), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1).
What is the impact of CVE-2014-3386?
The impact of CVE-2014-3386 is that remote attackers can exploit it to craft GTP packets, leading to a denial of service and device reload.
Is there a workaround for CVE-2014-3386?
There are no specific workarounds for CVE-2014-3386; upgrading to the patched version is the recommended action.