CVE-2014-2116: Input Validation
Published Apr 4, 2014
·Updated
Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject web pages and modify dynamic content via unspecified parameters, aka Bug ID CSCun37882.
Affected Software
1 affected component
Cisco Emergency Responder<=8.6
Event History
Apr 4, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:10 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2116?
CVE-2014-2116 is classified as a high severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2014-2116?
To fix CVE-2014-2116, upgrade Cisco Emergency Responder to version 8.6 or later.
3
Who is affected by CVE-2014-2116?
CVE-2014-2116 affects all versions of Cisco Emergency Responder up to and including 8.6.
4
What kind of attacks are possible with CVE-2014-2116?
CVE-2014-2116 allows remote attackers to inject web pages and alter dynamic content.
5
Is there a workaround for CVE-2014-2116?
There are no specifically recommended workarounds for CVE-2014-2116, but the best practice is to upgrade to a fixed version.