Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-3399

Опубликовано: 07 окт. 2014
Источник: nvd
CVSS2: 5.5
EPSS Низкий

Описание

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated users to overwrite arbitrary RAMFS cache files or inject Lua programs, and consequently cause a denial of service (portal outage or system reload), via crafted HTTP requests, aka Bug ID CSCup54208.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
Версия до 9.2\(2.4\) (включая)

EPSS

Процентиль: 31%
0.00115
Низкий

5.5 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
больше 3 лет назад

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated users to overwrite arbitrary RAMFS cache files or inject Lua programs, and consequently cause a denial of service (portal outage or system reload), via crafted HTTP requests, aka Bug ID CSCup54208.

EPSS

Процентиль: 31%
0.00115
Низкий

5.5 Medium

CVSS2

Дефекты

CWE-94