Vulnerabilities > Cisco > Intrusion Prevention System > 7.0

DATE CVE VULNERABILITY TITLE RISK
2014-10-19 CVE-2014-3406 Race Condition vulnerability in Cisco Intrusion Prevention System
Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085.
network
cisco CWE-362
7.1
2014-10-10 CVE-2014-3402 Improper Authentication vulnerability in Cisco Intrusion Prevention System
The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens, which allows remote attackers to cause a denial of service (temporary MainApp hang) via a crafted connection request to the management interface, aka Bug ID CSCuq39550.
network
low complexity
cisco CWE-287
5.0
2014-02-27 CVE-2014-2103 Improper Input Validation vulnerability in Cisco Intrusion Prevention System
Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP packets, aka Bug IDs CSCum52355 and CSCul49309.
network
low complexity
cisco CWE-20
6.8
2013-07-18 CVE-2013-3410 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco Intrusion Prevention System and IPS NME
Cisco Intrusion Prevention System (IPS) Software on IPS NME devices before 7.0(9)E4 allows remote attackers to cause a denial of service (device reload) via malformed IPv4 packets that trigger incorrect memory allocation, aka Bug ID CSCua61977.
network
low complexity
cisco CWE-119
7.8
2013-07-18 CVE-2013-1243 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco products
The IP stack in Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software and hardware modules before 7.1(5)E4, IPS 4500 sensors before 7.1(6)E4, and IPS 4300 sensors before 7.1(5)E4 allows remote attackers to cause a denial of service (MainApp process hang) via malformed IPv4 packets, aka Bug ID CSCtx18596.
network
low complexity
cisco CWE-119
7.8
2013-07-18 CVE-2013-1218 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco products
Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software modules before 7.1(7)sp1E4 allows remote attackers to cause a denial of service (Analysis Engine process hang or device reload) via fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCue51272.
network
low complexity
cisco CWE-119
7.8
2012-09-16 CVE-2012-3901 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco products
The updateTime function in sensorApp on Cisco IPS 4200 series sensors 7.0 and 7.1 allows remote attackers to cause a denial of service (process crash and traffic-inspection outage) via network traffic, aka Bug ID CSCta96144.
network
low complexity
cisco CWE-119
5.0
2012-09-16 CVE-2012-3899 Resource Management Errors vulnerability in Cisco products
sensorApp on Cisco IPS 4200 series sensors 6.0, 6.2, and 7.0 does not properly allocate memory, which allows remote attackers to cause a denial of service (memory corruption and process crash, and traffic-inspection outage) via network traffic, aka Bug ID CSCtn23051.
network
low complexity
cisco CWE-399
5.0
2012-05-03 CVE-2011-4022 Improper Authentication vulnerability in Cisco Intrusion Prevention System 7.0/7.1
The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and mainApp hang) by making authentication attempts that exceed the configured limit, aka Bug ID CSCto51204.
network
low complexity
cisco CWE-287
5.0