VULNERABILITY INTELLIGENCE
CVE-2014-3394
CVSS score5 MEDIUM
EPSS probability1.00%
CISA KEVNot currently listed
Published2014-10-10
Last modified2026-06-17
CVSS vectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Description
The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to bypass certificate validation via an arbitrary VeriSign certificate, aka Bug ID CSCun10916.
Weakness classification
- CWE-295: Improper Certificate Validation
Primary references
- psirt@cisco.com — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory