CVE Vulnerabilities

CVE-2014-3394

Improper Certificate Validation

Published: Oct 10, 2014 | Modified: Aug 15, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to bypass certificate validation via an arbitrary VeriSign certificate, aka Bug ID CSCun10916.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Adaptive_security_virtual_appliance Cisco - (including) - (including)
Adaptive_security_appliance_software Cisco 8.2.0.45 (including) 8.2.0.45 (including)
Adaptive_security_appliance_software Cisco 8.2.1 (including) 8.2.1 (including)
Adaptive_security_appliance_software Cisco 8.2.1.1 (including) 8.2.1.1 (including)
Adaptive_security_appliance_software Cisco 8.2.2 (including) 8.2.2 (including)
Adaptive_security_appliance_software Cisco 8.2.2.10 (including) 8.2.2.10 (including)
Adaptive_security_appliance_software Cisco 8.2.2.12 (including) 8.2.2.12 (including)
Adaptive_security_appliance_software Cisco 8.2.2.16 (including) 8.2.2.16 (including)
Adaptive_security_appliance_software Cisco 8.2.2.17 (including) 8.2.2.17 (including)
Adaptive_security_appliance_software Cisco 8.2.3 (including) 8.2.3 (including)
Adaptive_security_appliance_software Cisco 8.2.4 (including) 8.2.4 (including)
Adaptive_security_appliance_software Cisco 8.2.4.1 (including) 8.2.4.1 (including)
Adaptive_security_appliance_software Cisco 8.2.4.4 (including) 8.2.4.4 (including)
Adaptive_security_appliance_software Cisco 8.2.5 (including) 8.2.5 (including)
Adaptive_security_appliance_software Cisco 8.2.5.13 (including) 8.2.5.13 (including)
Adaptive_security_appliance_software Cisco 8.2.5.22 (including) 8.2.5.22 (including)
Adaptive_security_appliance_software Cisco 8.2.5.26 (including) 8.2.5.26 (including)
Adaptive_security_appliance_software Cisco 8.2.5.33 (including) 8.2.5.33 (including)
Adaptive_security_appliance_software Cisco 8.2.5.40 (including) 8.2.5.40 (including)
Adaptive_security_appliance_software Cisco 8.2.5.41 (including) 8.2.5.41 (including)
Adaptive_security_appliance_software Cisco 8.2.5.46 (including) 8.2.5.46 (including)
Adaptive_security_appliance_software Cisco 8.2.5.48 (including) 8.2.5.48 (including)
Adaptive_security_appliance_software Cisco 8.4.1 (including) 8.4.1 (including)
Adaptive_security_appliance_software Cisco 8.4.1.3 (including) 8.4.1.3 (including)
Adaptive_security_appliance_software Cisco 8.4.1.11 (including) 8.4.1.11 (including)
Adaptive_security_appliance_software Cisco 8.4.2 (including) 8.4.2 (including)
Adaptive_security_appliance_software Cisco 8.4.2.1 (including) 8.4.2.1 (including)
Adaptive_security_appliance_software Cisco 8.4.2.8 (including) 8.4.2.8 (including)
Adaptive_security_appliance_software Cisco 8.4.3 (including) 8.4.3 (including)
Adaptive_security_appliance_software Cisco 8.4.3.8 (including) 8.4.3.8 (including)
Adaptive_security_appliance_software Cisco 8.4.3.9 (including) 8.4.3.9 (including)
Adaptive_security_appliance_software Cisco 8.4.4 (including) 8.4.4 (including)
Adaptive_security_appliance_software Cisco 8.4.4.1 (including) 8.4.4.1 (including)
Adaptive_security_appliance_software Cisco 8.4.4.3 (including) 8.4.4.3 (including)
Adaptive_security_appliance_software Cisco 8.4.4.5 (including) 8.4.4.5 (including)
Adaptive_security_appliance_software Cisco 8.4.4.9 (including) 8.4.4.9 (including)
Adaptive_security_appliance_software Cisco 8.4.5 (including) 8.4.5 (including)
Adaptive_security_appliance_software Cisco 8.4.5.6 (including) 8.4.5.6 (including)
Adaptive_security_appliance_software Cisco 8.4.6 (including) 8.4.6 (including)
Adaptive_security_appliance_software Cisco 8.4.7 (including) 8.4.7 (including)
Adaptive_security_appliance_software Cisco 8.4.7.3 (including) 8.4.7.3 (including)
Adaptive_security_appliance_software Cisco 8.6.1 (including) 8.6.1 (including)
Adaptive_security_appliance_software Cisco 8.6.1.1 (including) 8.6.1.1 (including)
Adaptive_security_appliance_software Cisco 8.6.1.2 (including) 8.6.1.2 (including)
Adaptive_security_appliance_software Cisco 8.6.1.5 (including) 8.6.1.5 (including)
Adaptive_security_appliance_software Cisco 8.6.1.10 (including) 8.6.1.10 (including)
Adaptive_security_appliance_software Cisco 8.6.1.12 (including) 8.6.1.12 (including)
Adaptive_security_appliance_software Cisco 8.6.1.13 (including) 8.6.1.13 (including)
Adaptive_security_appliance_software Cisco 8.7.1 (including) 8.7.1 (including)
Adaptive_security_appliance_software Cisco 8.7.1.3 (including) 8.7.1.3 (including)
Adaptive_security_appliance_software Cisco 8.7.1.4 (including) 8.7.1.4 (including)
Adaptive_security_appliance_software Cisco 8.7.1.7 (including) 8.7.1.7 (including)
Adaptive_security_appliance_software Cisco 8.7.1.11 (including) 8.7.1.11 (including)
Adaptive_security_appliance_software Cisco 9.0.1 (including) 9.0.1 (including)
Adaptive_security_appliance_software Cisco 9.0.2 (including) 9.0.2 (including)
Adaptive_security_appliance_software Cisco 9.0.2.10 (including) 9.0.2.10 (including)
Adaptive_security_appliance_software Cisco 9.0.3 (including) 9.0.3 (including)
Adaptive_security_appliance_software Cisco 9.0.3.6 (including) 9.0.3.6 (including)
Adaptive_security_appliance_software Cisco 9.0.3.8 (including) 9.0.3.8 (including)
Adaptive_security_appliance_software Cisco 9.0.4 (including) 9.0.4 (including)
Adaptive_security_appliance_software Cisco 9.0.4.1 (including) 9.0.4.1 (including)
Adaptive_security_appliance_software Cisco 9.0.4.5 (including) 9.0.4.5 (including)
Adaptive_security_appliance_software Cisco 9.0.4.7 (including) 9.0.4.7 (including)
Adaptive_security_appliance_software Cisco 9.1.1 (including) 9.1.1 (including)
Adaptive_security_appliance_software Cisco 9.1.1.4 (including) 9.1.1.4 (including)
Adaptive_security_appliance_software Cisco 9.1.2 (including) 9.1.2 (including)
Adaptive_security_appliance_software Cisco 9.1.2.8 (including) 9.1.2.8 (including)
Adaptive_security_appliance_software Cisco 9.1.3 (including) 9.1.3 (including)
Adaptive_security_appliance_software Cisco 9.1.3.2 (including) 9.1.3.2 (including)
Adaptive_security_appliance_software Cisco 9.1.4 (including) 9.1.4 (including)
Adaptive_security_appliance_software Cisco 9.1.5 (including) 9.1.5 (including)

Potential Mitigations

References