SNMP Information Disclosure in Cisco NX-OS on Nexus 5000 and 6000 Devices
CVE-2014-3341

Currently unrated

Key Information:

Vendor

Cisco

Vendor
CVE Published:
19 August 2014

Badges

👾 Exploit Exists🟡 Public PoC🟣 EPSS 24%

What is CVE-2014-3341?

The SNMP module in Cisco NX-OS versions 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices allows remote attackers to exploit variations in error messages. This inconsistency permits attackers to identify existing VLANs through systematic queries, thereby compromising network integrity and security.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

24% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability Reserved

.
CVE-2014-3341 : SNMP Information Disclosure in Cisco NX-OS on Nexus 5000 and 6000 Devices