CVE-2014-5071: SQL Injection
Published Jan 8, 2018
·Updated
SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15 allows remote attackers to execute arbitrary SQL commands via vectors involving a username.
Affected Software
2 affected components
Microsemi S350i Firmware=2.70.15
Microsemi S350i
Event History
Jan 8, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2014-5071?
CVE-2014-5071 is a SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15.
2
How does CVE-2014-5071 affect Symmetricom s350i?
CVE-2014-5071 allows remote attackers to execute arbitrary SQL commands via vectors involving a username.
3
What is the severity of CVE-2014-5071?
CVE-2014-5071 has a severity rating of 9.8, which is considered critical.
4
How can I fix CVE-2014-5071?
To fix CVE-2014-5071, it is recommended to update the Symmetricom s350i firmware to version 2.70.15 or later.
5
Where can I find more information about CVE-2014-5071?
More information about CVE-2014-5071 can be found at the following link: [https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-5071/]