CVE-2014-3261

Published May 26, 2014

Last updated 18 days ago

Overview

Description
Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2 before 5.2(3a) on Nexus 7000 devices, and CG-OS CG4 before CG4(2) on Connected 1000 Connected Grid Routers allows remote SMTP servers to execute arbitrary code via a crafted reply, aka Bug IDs CSCtk00695, CSCts56633, CSCts56632, CSCts56628, CSCug14405, and CSCuf61322.
Source
psirt@cisco.com
NVD status
Modified
Products
unified_computing_system_6120xp_fabric_interconnect, unified_computing_system_6140xp_fabric_interconnect, unified_computing_system_6248up_fabric_interconnect, unified_computing_system_6296up_fabric_interconnect, unified_computing_system_infrastructure_and_unified_computing_system_software, cg-os, cgr_1120, cgr_1240, nx-os, nexus_7000, nexus_7000_10-slot, nexus_7000_18-slot, nexus_7000_9-slot, nexus_3016q, nexus_3048, nexus_3064t, nexus_3064x, nexus_3548, nexus_5000, nexus_5010, nexus_5010p_switch, nexus_5020, nexus_5020p_switch, nexus_5548p, nexus_5548up, nexus_5596up, nexus_4001i

Risk scores

CVSS 2.0

Type
Primary
Base score
7.6
Impact score
10
Exploitability score
4.9
Vector string
AV:N/AC:H/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-119

Social media

Hype score
Not currently trending

Configurations