CVE-2014-2137
 
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
CRLF injection vulnerability in the web framework in Cisco Web Security Appliance (WSA) 7.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCuj61002.
Vulnerabilidad de inyección CRLF en el framework web en Cisco Web Security Appliance (WSA) 7.7 y anteriores permite a atacantes remotos inyectar cabeceras HTTP arbitrarias y realizar ataques de redirección a través de una URL manipulada, también conocido como Bug ID CSCuj61002.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-02-25 CVE Reserved
- 2014-04-02 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2137 | 2014-04-02 | |
http://tools.cisco.com/security/center/viewAlert.x?alertId=33608 | 2014-04-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Web Security Virtual Appliance Search vendor "Cisco" for product "Web Security Virtual Appliance" | <= 7.7 Search vendor "Cisco" for product "Web Security Virtual Appliance" and version " <= 7.7" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Virtual Appliance Search vendor "Cisco" for product "Web Security Virtual Appliance" | 7.1.0 Search vendor "Cisco" for product "Web Security Virtual Appliance" and version "7.1.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Virtual Appliance Search vendor "Cisco" for product "Web Security Virtual Appliance" | 7.1.1 Search vendor "Cisco" for product "Web Security Virtual Appliance" and version "7.1.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Virtual Appliance Search vendor "Cisco" for product "Web Security Virtual Appliance" | 7.1.2 Search vendor "Cisco" for product "Web Security Virtual Appliance" and version "7.1.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Virtual Appliance Search vendor "Cisco" for product "Web Security Virtual Appliance" | 7.1.3 Search vendor "Cisco" for product "Web Security Virtual Appliance" and version "7.1.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Virtual Appliance Search vendor "Cisco" for product "Web Security Virtual Appliance" | 7.1.4 Search vendor "Cisco" for product "Web Security Virtual Appliance" and version "7.1.4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Virtual Appliance Search vendor "Cisco" for product "Web Security Virtual Appliance" | 7.5.0 Search vendor "Cisco" for product "Web Security Virtual Appliance" and version "7.5.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Virtual Appliance Search vendor "Cisco" for product "Web Security Virtual Appliance" | 7.5.1 Search vendor "Cisco" for product "Web Security Virtual Appliance" and version "7.5.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Web Security Appliance Search vendor "Cisco" for product "Web Security Appliance" | - | - |
Affected
|