CVE-2014-3390: Input Validation
The Virtual Network Management Center (VNMC) policy implementation in Cisco ASA Software 8.7 before 8.7(1.14), 9.2 before 9.2(2.8), and 9.3 before 9.3(1.1) allows local users to obtain Linux root access by leveraging administrative privileges and executing a crafted script, aka Bug IDs CSCuq41510 and CSCuq47574.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3390?
CVE-2014-3390 has a critical severity rating due to the potential for local users to obtain Linux root access.
How do I fix CVE-2014-3390?
To fix CVE-2014-3390, upgrade to Cisco ASA Software version 8.7(1.14), 9.2(2.8), or 9.3(1.1) or later.
Who is affected by CVE-2014-3390?
CVE-2014-3390 affects users of Cisco ASA Software versions prior to the specified patches.
What can attackers do with CVE-2014-3390?
Attackers with local administrative privileges can exploit CVE-2014-3390 to execute malicious scripts and gain root access.
What type of vulnerability is CVE-2014-3390?
CVE-2014-3390 is a local privilege escalation vulnerability.