5.4

CVE-2014-7994

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to an unspecified HTTP handler on the local network, aka Cisco-Meraki defect ID 00301991.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Meraki Mr Firmware Version <= 2014-09-24
Cisco ≫ Meraki Mr Version -
Cisco ≫ Meraki Mx Firmware Version <= 2014-09-24
Cisco ≫ Meraki Mx Version -
Cisco ≫ Meraki Ms Firmware Version <= 2014-09-24
Cisco ≫ Meraki Ms Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.68% 0.474
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 5.5 6.4
AV:A/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://dashboard.meraki.com/firmware_security
http://tools.cisco.com/security/center/viewAlert.x?alertId=36798
Vendor Advisory