CVE-2014-2974: CSRF
Published Jul 28, 2014
·Updated
Cross-site request forgery (CSRF) vulnerability in php/useraccount.php in Silver Peak VX through 6.2.4 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.
Affected Software
2 affected components
Silver-peak Vx<=6.2.4
Silver-peak Vx=6.2.2.0_47968
Event History
Jul 28, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2974?
CVE-2014-2974 is classified as a high severity vulnerability due to its potential to allow remote attackers to hijack administrator authentication.
2
How do I fix CVE-2014-2974?
To fix CVE-2014-2974, update Silver Peak VX to the latest version that is above 6.2.4.
3
Who is affected by CVE-2014-2974?
CVE-2014-2974 affects users of Silver Peak VX versions up to and including 6.2.4.
4
What type of vulnerability is CVE-2014-2974?
CVE-2014-2974 is a Cross-site Request Forgery (CSRF) vulnerability.
5
What can an attacker do with CVE-2014-2974?
An attacker exploiting CVE-2014-2974 can potentially create administrative accounts by hijacking the authentication of legitimate administrators.