CVE-2014-3261: Cisco Cg-OS

High severity, CVSS 7.6. EPSS: 2% chance of exploitation in the next 30 days.

Buffer overflow in the Smart Call Home implementation in Cisco NX-OS on Fabric Interconnects in Cisco Unified Computing System 1.4 before 1.4(1i), NX-OS 5.0 before 5.0(3)U2(2) on Nexus 3000 devices, NX-OS 4.1 before 4.1(2)E1(1l) on Nexus 4000 devices, NX-OS 5.x before 5.1(3)N1(1) on Nexus 5000 devices, NX-OS 5.2 before 5.2(3a) on Nexus 7000 devices, and CG-OS CG4 before CG4(2) on Connected 1000 Connected Grid Routers allows remote SMTP servers to execute arbitrary code via a crafted reply, aka Bug IDs CSCtk00695, CSCts56633, CSCts56632, CSCts56628, CSCug14405, and CSCuf61322.

Affected products

  • Cisco Cg-OS: version cg4 only; version cg4(1) only
  • Cisco Cgr 1120
  • Cisco Cgr 1240
  • Cisco Nexus 3016q
  • Cisco Nexus 3048
  • Cisco Nexus 3064t
  • Cisco Nexus 3064x
  • Cisco Nexus 3548
  • Cisco Nexus 4001i
  • Cisco Nexus 5000
  • Cisco Nexus 5010
  • Cisco Nexus 5010p Switch
  • Cisco Nexus 5020
  • Cisco Nexus 5020p Switch
  • Cisco Nexus 5548p
  • Cisco Nexus 5548up
  • Cisco Nexus 5596up
  • Cisco Nexus 7000
  • Cisco Nexus 7000 10-Slot
  • Cisco Nexus 7000 18-Slot
  • Cisco Nexus 7000 9-Slot
  • Cisco NX-OS: version 5.2 only; version 5.2(1) only; version 5.2(3) only; affected versions not specified; version 5.0 only; version 5.0(2) only; …
  • Cisco Unified Computing System 6120xp Fabric Interconnect: affected versions not specified
  • Cisco Unified Computing System 6140xp Fabric Interconnect: affected versions not specified
  • Cisco Unified Computing System 6248up Fabric Interconnect: affected versions not specified
  • and 2 more

Published 2014-05-26. Last modified 2026-06-17.