Cisco Bug: CSCup24089 - Multiple Vulnerabilities in OpenSSL - June 2014
Jan 29, 2017
- Cisco Policy Suite for Mobile
Known Affected Releases
Symptom: The following Cisco products Quantum Policy Suite Version 7 (7.0.0) include a version of openssl that may be affected by the vulnerabilities identified by the following Common Vulnerability and Exposures (CVE) IDs: CVE-2010-5298 - SSL_MODE_RELEASE_BUFFERS session injection or denial of service CVE-2014-0076 - Fix for the attack described in the paper "Recovering OpenSSL ECDSA Nonces Using the FLUSH+RELOAD Cache Side-channel Attack" CVE-2014-0195 - DTLS invalid fragment vulnerability CVE-2014-0198 - SSL_MODE_RELEASE_BUFFERS NULL pointer dereference CVE-2014-0221 - DTLS recursion flaw CVE-2014-0224 - SSL/TLS MITM vulnerability CVE-2014-3470 - Anonymous ECDH denial of service This bug has been opened to address the potential impact on this product. Conditions: Devices running a version of Quantum Policy Suite (QPS) prior to 7.0.0 may be affected by one or more of the CVE's documented in this note.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases