CVE-2014-3406: Race Condition
Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3406?
CVE-2014-3406 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2014-3406?
To fix CVE-2014-3406, upgrade your Cisco Intrusion Prevention System to a version later than 7.1(7)E4 that addresses this vulnerability.
Who is affected by CVE-2014-3406?
CVE-2014-3406 affects Cisco Intrusion Prevention Systems running version 7.1(7)E4 and earlier.
What type of attack does CVE-2014-3406 involve?
CVE-2014-3406 involves remote attackers exploiting a race condition in IP logging to trigger a denial of service.
What are the consequences of CVE-2014-3406?
The consequence of CVE-2014-3406 is that it can cause the affected device to reload, leading to temporary service disruption.