CVE-2014-2046: Critical severity Broadcom Pipa C211 Web Interface vulnerability
cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obtain credentials and other sensitive information via a certain request to the config.getValuesHashExcludePaths method or (2) modify the firmware via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2046?
CVE-2014-2046 is considered a high severity vulnerability due to its potential for remote attacks that can expose sensitive information and allow firmware modification.
How do I fix CVE-2014-2046?
To fix CVE-2014-2046, update the Broadcom Pipa C211 web interface to the latest version that addresses this vulnerability.
What type of access does CVE-2014-2046 allow for attackers?
CVE-2014-2046 allows remote attackers to obtain sensitive information including credentials and, in some cases, modify the device's firmware.
Which versions are affected by CVE-2014-2046?
CVE-2014-2046 affects Broadcom Pipa C211 web interface version 1.1 and the hardware revision rev2.
Is CVE-2014-2046 exploitable over the internet?
Yes, CVE-2014-2046 can be exploited remotely, making it a significant risk for internet-facing devices.