CVE-2014-3331
CVE-2014-3331 is a medium-severity vulnerability in Cisco Asr 5000 Series Software with a CVSS 2.0 base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Medium (CVSS 2.0 base score 4.3)
- EPSS exploit prediction: 2% (77th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-20
- Affected product: Cisco Asr 5000 Series Software
- Published:
- Last modified:
Description
The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11.0, 12.0, 12.1, 12.2, 14.0, 15.0, 16.x through 16.1.2, and 17.0 allows remote attackers to cause a denial of service (process crash) via a crafted TCP packet, aka Bug ID CSCuo21914.
Frequently asked questions
- What is CVE-2014-3331?
- The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11.0, 12.0, 12.1, 12.2, 14.0, 15.0, 16.x through 16.1.2, and 17.0 allows remote attackers to cause a denial of service (process crash) via a crafted TCP packet, aka Bug ID CSCuo21914.
- How severe is CVE-2014-3331?
- CVE-2014-3331 has a CVSS 2.0 base score of 4.3, rated medium severity.
- Is CVE-2014-3331 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (77th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2014-3331?
- CVE-2014-3331 primarily affects Cisco Asr 5000 Series Software. In total, 10 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2014-3331?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2014-3331 published?
- CVE-2014-3331 was published on 2014-08-20 and last updated on 2026-06-17.
References
- http://secunia.com/advisories/60706
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3331
- http://tools.cisco.com/security/center/viewAlert.x?alertId=35346
- http://www.securityfocus.com/bid/69281
- http://www.securitytracker.com/id/1030747
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95357
Affected products (10)
- cpe:2.3:a:cisco:asr_5000_series_software:11.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:asr_5000_series_software:12.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:asr_5000_series_software:12.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:asr_5000_series_software:12.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:asr_5000_series_software:14.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:asr_5000_series_software:15.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:asr_5000_series_software:16.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:asr_5000_series_software:16.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:asr_5000_series_software:16.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:asr_5000_series_software:17.0.0:*:*:*:*:*:*:*
More vulnerabilities in Cisco Asr 5000 Series Software
- CVE-2017-3819 — High (CVSS 8.8): A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR…
- CVE-2017-6612 — High (CVSS 8.6): A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers…
- CVE-2017-6672 — High (CVSS 7.5): A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation…
- CVE-2016-9203 — High (CVSS 7.5): A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco ASR 5000 Series Software could allow an…
- CVE-2016-6467 — High (CVSS 7.5): A vulnerability in IPv6 packet fragment reassembly of StarOS for Cisco Aggregation Services Router (ASR) 5000 Series…
- CVE-2016-6466 — High (CVSS 7.5): A vulnerability in the IPsec component of StarOS for Cisco ASR 5000 Series routers could allow an unauthenticated,…
All CVEs affecting Cisco Asr 5000 Series Software →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-93952 — Critical (CVSS 10.0): VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access…
- CVE-2026-77554 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-77537 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →