CVE-2014-2126: High severity Cisco Adaptive Security Appliance Software vulnerability
Published Apr 10, 2014
·Updated
Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 before 8.7(1.11), 9.0 before 9.0(3.10), and 9.1 before 9.1(3.4) allows remote authenticated users to gain privileges by leveraging level-0 ASDM access, aka Bug ID CSCuj33496.
Affected Software
5 affected components
Cisco Adaptive Security Appliance Software=8.2
Cisco Adaptive Security Appliance Software=8.4
Cisco Adaptive Security Appliance Software=8.7
Cisco Adaptive Security Appliance Software=9.0
Cisco Adaptive Security Appliance Software=9.1
Event History
Apr 10, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·04:34 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2126?
CVE-2014-2126 is rated as a medium severity vulnerability.
2
How do I fix CVE-2014-2126?
To fix CVE-2014-2126, upgrade to version 8.2(5.47), 8.4(7.5), 8.7(1.11), 9.0(3.10), or 9.1(3.4) or later of the Cisco Adaptive Security Appliance Software.
3
What types of access does CVE-2014-2126 affect?
CVE-2014-2126 affects remote authenticated users with level-0 ASDM access.
4
What software is affected by CVE-2014-2126?
CVE-2014-2126 affects Cisco Adaptive Security Appliance Software versions 8.2, 8.4, 8.7, 9.0, and 9.1.
5
Can CVE-2014-2126 be exploited remotely?
Yes, CVE-2014-2126 can be exploited remotely by authenticated users.