CVE-2014-5502: OS Command Injection
The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcertkey, (2) webclientportalsettings, (3) sslvpnliveuserdelete, or (4) cccflushsqlfile opcode.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5502?
CVE-2014-5502 is classified as a high severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2014-5502?
To remediate CVE-2014-5502, upgrade Sophos Cyberoam appliances with CyberoamOS to version 10.6.1 GA or later.
Who is affected by CVE-2014-5502?
CVE-2014-5502 affects remote authenticated users of Sophos Cyberoam appliances running vulnerable versions of CyberoamOS.
What types of commands can be injected in CVE-2014-5502?
CVE-2014-5502 allows the injection of arbitrary commands through specific opcodes like checkcert_key and sslvpn_liveuser_delete.
Is CVE-2014-5502 easy to exploit?
Exploitation of CVE-2014-5502 requires authenticated access, making it less accessible to unauthenticated attackers.