← Voltar para CVEs
CVE-2014-7994
N/ADescricao
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to an unspecified HTTP handler on the local network, aka Cisco-Meraki defect ID 00301991.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado12/24/2014
Ultima modificacao4/12/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
cisco:meraki_mrcisco:meraki_mr_firmwarecisco:meraki_mscisco:meraki_ms_firmwarecisco:meraki_mxcisco:meraki_mx_firmware
Fraquezas (CWE)
CWE-20
Referencias
http://tools.cisco.com/security/center/viewAlert.x?alertId=36798(psirt@cisco.com)
https://dashboard.meraki.com/firmware_security(psirt@cisco.com)
http://tools.cisco.com/security/center/viewAlert.x?alertId=36798(af854a3a-2127-422b-91ae-364da2661108)
https://dashboard.meraki.com/firmware_security(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.