CVE-2014-3331 describes a denial-of-service vulnerability in the Session Manager component of Cisco ASR 5000 Series Software, specifically affecting Packet Data Network Gateway (PGW) versions 11.0 through 17.0. Remote attackers can exploit this flaw by sending a specially crafted TCP packet, leading to a process crash. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity (AC:M) and potential for partial availability impact (A:P), without requiring authentication (Au:N) or network access (AV:N). Its EPSS and FAUCET Risk Scores are low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation, nor are there any public exploit codes available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also absent, indicating a lack of widespread attention or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:a:cisco:asr_5000_series_software:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:cisco:asr_5000_series_software:12.0:*:*:*:*:*:*:* | ||
12.1CPE matchmatch criteria | cpe:2.3:a:cisco:asr_5000_series_software:12.1:*:*:*:*:*:*:* | ||
12.2CPE matchmatch criteria | cpe:2.3:a:cisco:asr_5000_series_software:12.2:*:*:*:*:*:*:* | ||
14.0CPE matchmatch criteria | cpe:2.3:a:cisco:asr_5000_series_software:14.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.