First published: Thu Jun 05 2014(Updated: )
Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long session id in the URI to sys_reboot.html. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
A10 Networks Advanced Core Operating System | =2.7.0 | |
A10 Networks Advanced Core Operating System | =2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3976 has a high severity rating due to the potential for remote denial of service and arbitrary code execution.
To fix CVE-2014-3976, upgrade the A10 Networks Advanced Core Operating System to version 2.7.0-p6 or 2.7.1-P1_55 or later.
CVE-2014-3976 affects A10 Networks Advanced Core Operating System version 2.7.0 and 2.7.1 before 2.7.1-P1_55.
CVE-2014-3976 is classified as a buffer overflow vulnerability.
By exploiting CVE-2014-3976, attackers can crash the system and potentially execute arbitrary code remotely.