Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-7994

Overview

Vulnerability Score 5.4 5.4
CVE Id CVE-2014-7994
Last Modified 24 Dec 2014 10:38:44
Published 23 Dec 2014 07:59:01
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector ADJACENT_NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2014-7994

Summary

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to an unspecified HTTP handler on the local network, aka Cisco-Meraki defect ID 00301991.

Vulnerable Systems

Application

  • Cisco Meraki Mr Firmware 2014-09-24

  • Cisco Meraki Ms Firmware 2014-09-24

  • Cisco Meraki Mx Firmware 2014-09-24


References

CONFIRM - https://dashboard.meraki.com/firmware_security

CONFIRM - http://tools.cisco.com/security/center/viewAlert.x?alertId=36798


Last Updated: 27 May 2016 11:07:22