First published: Fri May 23 2014(Updated: )
Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allows remote SharePoint servers to execute arbitrary code via a malformed response, aka Bug ID CSCue18479.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Wide Area Application Services | =5.1.1 | |
Cisco Wide Area Application Services | =5.1.1-a | |
Cisco Wide Area Application Services | =5.1.1-b | |
Cisco Wide Area Application Services | =5.1.1-c | |
Cisco Wide Area Application Services | =5.1.1-d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2196 has a severity rating of high due to the potential for remote code execution.
To fix CVE-2014-2196, upgrade Cisco Wide Area Application Services to version 5.1.1e or later.
CVE-2014-2196 affects Cisco Wide Area Application Services version 5.1.1 and its subversions.
Yes, CVE-2014-2196 can be exploited remotely by attackers sending malformed responses to vulnerable SharePoint servers.
If exploited successfully, CVE-2014-2196 could allow an attacker to execute arbitrary code on the affected system.