CVE-2014-7990: Input Validation
Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7990?
CVE-2014-7990 is considered a critical vulnerability, as it allows local users to gain Linux root access on affected Cisco devices.
How do I fix CVE-2014-7990?
To mitigate CVE-2014-7990, upgrade affected Cisco IOS XE devices to a version later than 3.5E.
Which devices are affected by CVE-2014-7990?
CVE-2014-7990 impacts Cisco IOS XE 3.5E and earlier versions on WS-C3850, WS-C3860, and AIR-CT5760 devices.
Can CVE-2014-7990 allow unauthorized access?
Yes, CVE-2014-7990 can be exploited by local users with administrative privileges to gain unauthorized root access.
Is there a workaround for CVE-2014-7990?
The best approach for CVE-2014-7990 is to apply the necessary software updates, as no practical workaround is available.