CVE-2014-3261 - CVE House
Back to Database
Status published High CVE-2014-3261

Buffer overflow in the Smart Call Home implementation in Cisco...

Vulnerability Description

Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2 before 5.2(3a) on Nexus 7000 devices, and CG-OS CG4 before CG4(2) on Connected 1000 Connected Grid Routers allows remote SMTP servers to execute arbitrary code via a crafted reply, aka Bug IDs CSCtk00695, CSCts56633, CSCts56632, CSCts56628, CSCug14405, and CSCuf61322.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-3261

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

unified computing system 6120xp fabric interconnect, unified computing system 6140xp fabric interconnect, unified computing system 6248up fabric interconnect, unified computing system 6296up fabric interconnect, unified computing system infrastructure and unified computing system software, cg-os, cgr 1120, cgr 1240, nx-os, nexus 7000, nexus 7000 10-slot, nexus 7000 18-slot, nexus 7000 9-slot, nexus 3016q, nexus 3048, nexus 3064t, nexus 3064x, nexus 3548, nexus 5000, nexus 5010, nexus 5010p switch, nexus 5020, nexus 5020p switch, nexus 5548p, nexus 5548up, nexus 5596up, nexus 4001i
Vulnerable Versions:
1.4\(1j\), cg4, cg4\(1\), 5.2, 5.2\(1\), 5.2\(3\), 5.0, 5.0\(2\), 5.0\(2\)n1\(1\), 5.0\(2\)n2\(1\), 5.0\(2\)n2\(1a\), 5.0\(2a\), 5.0\(3\), 5.0\(3\)n1\(1\), 5.0\(3\)n1\(1a\), 5.0\(3\)n1\(1b\), 5.0\(3\)n1\(1c\), 5.0\(3\)n2\(1\), 5.0\(3\)n2\(2\), 5.0\(3\)n2\(2a\), 5.0\(3\)n2\(2b\), 5.0\(3\)u1\(1a\), 5.0\(3\)u1\(1b\), 5.0\(3\)u1\(1d\), 5.0\(3\)u1\(2\), 5.0\(3\)u1\(2a\), 5.0\(3\)u2\(1\), 5.0\(3\)u2\(2\), 5.0\(3\)u2\(2a\), 5.0\(3\)u2\(2b\), 5.0\(3\)u2\(2c\), 5.0\(3\)u2\(2d\), 5.0\(3\)u3\(1\), 5.0\(3\)u3\(2\), 5.0\(3\)u3\(2a\), 5.0\(3\)u3\(2b\), 5.0\(3\)u4\(1\), 5.0\(3\)u5\(1\), 5.0\(3\)u5\(1a\), 5.0\(3\)u5\(1b\), 5.0\(3\)u5\(1c\), 5.0\(3\)u5\(1d\), 5.0\(3\)u5\(1e\), 5.0\(5\), 5.1, 5.1\(1\), 5.1\(1a\), 5.1\(2\), 5.1\(3\), 4.1.\(2\)

Timeline

Official Publish: May 24th, 2014
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.