CVE-2014-7990
 
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815.
Cisco IOS XE 3.5E y anteriores en los dispositivos WS-C3850, WS-C3860, y AIR-CT5760 no analiza debidamente la respuesta al reto 'solicitar el shell del sistema', lo que permite a usuarios locales obtener acceso al root de Linux mediante el aprovechamiento de privilegios administrativos, tambiƩn conocido como Bug ID CSCur09815.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-10-08 CVE Reserved
- 2014-11-07 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/70968 | Vdb Entry | |
http://www.securitytracker.com/id/1031179 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/98529 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7990 | 2017-09-08 | |
http://tools.cisco.com/security/center/viewAlert.x?alertId=36351 | 2017-09-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | <= 3.5e Search vendor "Cisco" for product "Ios Xe" and version " <= 3.5e" | - |
Affected
| in | Cisco Search vendor "Cisco" | Air-ct5760 Search vendor "Cisco" for product "Air-ct5760" | * | - |
Affected
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | <= 3.5e Search vendor "Cisco" for product "Ios Xe" and version " <= 3.5e" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ws-c3850 Search vendor "Cisco" for product "Ws-c3850" | * | - |
Affected
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | <= 3.5e Search vendor "Cisco" for product "Ios Xe" and version " <= 3.5e" | - |
Affected
| in | Cisco Search vendor "Cisco" | Ws-c3860 Search vendor "Cisco" for product "Ws-c3860" | * | - |
Affected
|