CVE-2014-2117: Input Validation
Published Apr 4, 2014
·Updated
Multiple open redirect vulnerabilities in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters, aka Bug ID CSCun37909.
Affected Software
1 affected component
Cisco Emergency Responder<=8.6
Event History
Apr 4, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:10 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2117?
CVE-2014-2117 has been rated as medium severity due to its potential for allowing phishing attacks.
2
How do I fix CVE-2014-2117?
To fix CVE-2014-2117, users should upgrade to a version of Cisco Emergency Responder that is later than 8.6.
3
What systems are affected by CVE-2014-2117?
CVE-2014-2117 affects Cisco Emergency Responder versions 8.6 and earlier.
4
What kind of attacks can CVE-2014-2117 enable?
CVE-2014-2117 can enable remote attackers to conduct phishing attacks via open redirect vulnerabilities.
5
Are there any workarounds for CVE-2014-2117?
There are no specific workarounds available for CVE-2014-2117; upgrading the software is the recommended action.