CVE-2014-4870: Input Validation
/opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate parameters, which allows local users to gain privileges by leveraging the sudo configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4870?
CVE-2014-4870 has a CVSS score indicating a medium severity vulnerability due to improper parameter validation allowing privilege escalation.
How do I fix CVE-2014-4870?
To fix CVE-2014-4870, update the Brocade Vyatta 5400 vRouter software to a patched version that addresses the improper validation.
Who is affected by CVE-2014-4870?
CVE-2014-4870 affects local users of the Brocade Vyatta 5400 vRouter versions 6.4, 6.6, and 6.7.
Is CVE-2014-4870 exploitable remotely or locally?
CVE-2014-4870 is exploitable locally as it requires authenticated access to the affected system.
What can attackers potentially do with CVE-2014-4870?
Attackers can gain elevated privileges on the system due to the vulnerable parameter validation in the sudo configuration.