CVE-2014-3394: Cisco Adaptive Security Appliance Software
Medium severity, CVSS 5.0. EPSS: 1% chance of exploitation in the next 30 days.
The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to bypass certificate validation via an arbitrary VeriSign certificate, aka Bug ID CSCun10916.
Affected products
- Cisco Adaptive Security Appliance Software: version 8.2.0.45 only; version 8.2.1 only; version 8.2.1.1 only; version 8.2.2 only; version 8.2.2.10 only; version 8.2.2.12 only; …
- Cisco Adaptive Security Virtual Appliance: affected versions not specified
Published 2014-10-10. Last modified 2026-06-17.