CVE-2014-3261
CVE-2014-3261 is a high-severity vulnerability in Cisco Unified Computing System 6120xp Fabric Interconnect with a CVSS 2.0 base score of 7.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-119.
Key facts
- Severity: High (CVSS 2.0 base score 7.6)
- EPSS exploit prediction: 2% (80th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-119
- Affected product: Cisco Unified Computing System 6120xp Fabric Interconnect
- Published:
- Last modified:
Description
Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2 before 5.2(3a) on Nexus 7000 devices, and CG-OS CG4 before CG4(2) on Connected 1000 Connected Grid Routers allows remote SMTP servers to execute arbitrary code via a crafted reply, aka Bug IDs CSCtk00695, CSCts56633, CSCts56632, CSCts56628, CSCug14405, and CSCuf61322.
Frequently asked questions
- What is CVE-2014-3261?
- Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2 before 5.2(3a) on Nexus 7000 devices, and CG-OS CG4 before CG4(2) on Connected 1000 Connected Grid Routers allows remote SMTP servers to execute arbitrary code via a crafted reply, aka Bug IDs CSCtk00695, CSCts56633, CSCts56632, CSCts56628, CSCug14405, and CSCuf61322.
- How severe is CVE-2014-3261?
- CVE-2014-3261 has a CVSS 2.0 base score of 7.6, rated high severity.
- Is CVE-2014-3261 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (80th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2014-3261?
- CVE-2014-3261 primarily affects Cisco Unified Computing System 6120xp Fabric Interconnect. In total, 75 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2014-3261?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2014-3261 published?
- CVE-2014-3261 was published on 2014-05-26 and last updated on 2026-06-17.
References
Affected products (75)
- cpe:2.3:h:cisco:unified_computing_system_6120xp_fabric_interconnect:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:unified_computing_system_6140xp_fabric_interconnect:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:unified_computing_system_6248up_fabric_interconnect:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:unified_computing_system_6296up_fabric_interconnect:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:unified_computing_system_infrastructure_and_unified_computing_system_software:1.4\(1j\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:cg-os:cg4:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:cg-os:cg4\(1\):*:*:*:*:*:*:*
- cpe:2.3:h:cisco:cgr_1120:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:cgr_1240:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.2:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.2\(1\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.2\(3\):*:*:*:*:*:*:*
- cpe:2.3:h:cisco:nexus_7000:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:nexus_7000_10-slot:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:nexus_7000_18-slot:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:nexus_7000_9-slot:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:-:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(2\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(2\)n1\(1\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(2\)n2\(1\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(2\)n2\(1a\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(2a\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)n1\(1\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)n1\(1a\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)n1\(1b\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)n1\(1c\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)n2\(1\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)n2\(2\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)n2\(2a\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)n2\(2b\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)u1\(1a\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)u1\(1b\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)u1\(1d\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)u1\(2\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)u1\(2a\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:nx-os:5.0\(3\)u2\(1\):*:*:*:*:*:*:*
- cpe:2.3:h:cisco:nexus_3016q:-:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:nexus_3048:-:*:*:*:*:*:*:*
More vulnerabilities in Cisco Unified Computing System 6120xp Fabric Interconnect
- CVE-2013-1183 — Critical (CVSS 10.0): Buffer overflow in the Intelligent Platform Management Interface (IPMI) functionality in the Manager component in Cisco…
- CVE-2013-1185 — Critical (CVSS 9.3): The web interface in the Manager component in Cisco Unified Computing System (UCS) 1.x and 2.x before 2.0(2m) allows…
- CVE-2013-1182 — Critical (CVSS 9.3): The login page in the Web Console in the Manager component in Cisco Unified Computing System (UCS) before 1.0(2h), 1.1…
- CVE-2013-1178 — High (CVSS 8.3): Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x…
- CVE-2013-1184 — High (CVSS 7.8): The management API in the XML API management service in the Manager component in Cisco Unified Computing System (UCS)…
- CVE-2013-1186 — High (CVSS 7.5): Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM…
All CVEs affecting Cisco Unified Computing System 6120xp Fabric Interconnect →
Other CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) vulnerabilities
- CVE-2026-105285 — Critical (CVSS 10.0): A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function…
- CVE-2026-104610 — Critical (CVSS 10.0): A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function…
- CVE-2026-101039 — Critical (CVSS 10.0): A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element…
- CVE-2026-96257 — Critical (CVSS 10.0): A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element…
- CVE-2026-94089 — Critical (CVSS 10.0): A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file…
- CVE-2026-94003 — Critical (CVSS 10.0): A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file…