Guest

Preview Tool

Cisco Bug: CSCup22656 - Multiple Vulnerabilities in OpenSSL - June 2014

Last Modified

Dec 15, 2019

Products (1)

  • Cisco Universal Small Cell 3000 Series

Known Affected Releases

V3.4.1.18 V3.4.2.12 V3.4.2.8

Description (partial)

Symptom:
The following Cisco products

-          DPH-SO16 (Cisco, formerly Ubiquisys)
-          FAPE-HSP-5620 (OEM)
-          FAPO-HSP-5900 (OEM)
-          FAPR-HSP-5110 (OEM)
-          FC1020 (Cisco, formerly Ubiquisys)
-          FC1021 (Cisco, formerly Ubiquisys)
-          FC1022 (Cisco, formerly Ubiquisys)
-          FC1060 (Cisco, formerly Ubiquisys)
-          FC1080 (Cisco, formerly Ubiquisys)
-          FC170U (Cisco, formerly Ubiquisys)
-          FC173U (Cisco, formerly Ubiquisys)
-          FC233U (Cisco, formerly Ubiquisys)
-          FC235U (Cisco, formerly Ubiquisys)
-          FC270U (Cisco, formerly Ubiquisys)
-          FEMTO-G3 (Cisco, formerly Ubiquisys)
-          FEMTOAP-SR1 (Cisco, formerly Ubiquisys)
-          FEMTOAP-SR2 (Cisco, formerly Ubiquisys)
-          FMA16301T (OEM)
-          FP16201 (OEM)
-          FP8101 (OEM)
-          FP8131T (OEM)
-          FPA16241T (OEM)
-          FPLUS2 (Cisco, formerly Ubiquisys)
-          G5 (Cisco, formerly Ubiquisys)
-          G6 (Cisco, formerly Ubiquisys)
-          S2000 (OEM)
-          SH170U (Cisco, formerly Ubiquisys)
-          SH173U (Cisco, formerly Ubiquisys)
-          USC3331 (Cisco)
-          USC5310 (Cisco)
-          USC5330 (Cisco)
-          USC7330 (Cisco)
-          USC9330 (Cisco)
-          ZM-000-05-0005 (Cisco, formerly Ubiquisys)
-          ZP-000-05EU-0004 (Cisco, formerly Ubiquisys)
-          ZP-000-07EU-0001 (Cisco, formerly Ubiquisys)
-          ZP-001-03EU-0003 (Cisco, formerly Ubiquisys)
-          ZP-001-03EU-0005 (Cisco, formerly Ubiquisys)
-          ZP-001-03EU-0006 (Cisco, formerly Ubiquisys)
-          ZP-005-02EU-0002 (Cisco, formerly Ubiquisys)

running software versions

SCS1.0/SCS2.0 - V3.4.2.18-V3.4.2.29
SCS3.0 (pre-FCS) - V3.4.3.6-V3.4.3.8
Factory Recovery RootFS - V2.99.9

include a version of openssl that is affected by the vulnerabilities identified by the Common Vulnerability and Exposures (CVE) IDs:

CVE-2014-0224 - SSL/TLS MITM vulnerability
CVE-2014-3470 - Anonymous ECDH denial of service

This bug has been opened to address the potential impact on this product.

Conditions:
Devices with default configuration during factory recovery where the Factory Recovery RootFS sets up a HTTPS connection to Cloudbase are affected.
Devices configured in Cisco solution mode where all OAM communications use TLS are affected.
Devices configured in partner modes where OAM communications go via the IPSEC tunnel are NOT affected.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.