CVE-2014-0659: OS Command Injection
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0659?
CVE-2014-0659 has a high CVSS score due to its potential for unauthorized access to sensitive configuration and credential data.
How do I fix CVE-2014-0659?
To fix CVE-2014-0659, update the firmware of the affected Cisco devices to the latest available version.
Which Cisco devices are affected by CVE-2014-0659?
CVE-2014-0659 affects the Cisco WAP4410N, WRVS4400N, and RVS4000 devices with specific firmware versions.
Can CVE-2014-0659 be exploited remotely?
Yes, CVE-2014-0659 can be exploited remotely, allowing attackers to read credentials and execute commands without physical access.
What type of vulnerabilities does CVE-2014-0659 represent?
CVE-2014-0659 represents a number of vulnerabilities that involve improper input validation and lack of authentication for sensitive operations.