CVE-2014-3407

medium Cisco
CVSS v3 Base Score
5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS Score
0.4%
Exploitation probability in 30 days
Top 40% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
None
Availability
P
Published: November 28, 2014 (4185 days ago)
Last Modified: May 6, 2026
Vendor: Cisco
Source: NVD

Description

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCuq68888.

CWE

CWE-400

Affected Products

cisco adaptive security appliance software

References