Guest

Preview Tool

Cisco Bug: CSCup24089 - Multiple Vulnerabilities in OpenSSL - June 2014

Last Modified

Jan 29, 2017

Products (1)

  • Cisco Policy Suite for Mobile

Known Affected Releases

6.0.0

Description (partial)

Symptom:
The following Cisco products

Quantum Policy Suite Version 7 (7.0.0)
 
include a version of openssl that may be affected by the vulnerabilities identified by the following Common Vulnerability and Exposures (CVE) IDs:

CVE-2010-5298 - SSL_MODE_RELEASE_BUFFERS session injection or denial of service
CVE-2014-0076 - Fix for the attack described in the paper "Recovering OpenSSL ECDSA Nonces Using the FLUSH+RELOAD Cache Side-channel Attack"
CVE-2014-0195 - DTLS invalid fragment vulnerability
CVE-2014-0198 - SSL_MODE_RELEASE_BUFFERS NULL pointer dereference
CVE-2014-0221 - DTLS recursion flaw
CVE-2014-0224 - SSL/TLS MITM vulnerability
CVE-2014-3470 - Anonymous ECDH denial of service

This bug has been opened to address the potential impact on this product.

Conditions:
Devices running a version of Quantum Policy Suite (QPS) prior to 7.0.0 may be affected by one or more of the CVE's documented in this note.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.