SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0343

The web interface on Virtual Access GW6110A routers with software 9.00 before 9.09.27, 9.50 before 9.50.21, and 10.00 before 10.00.21 allows remote authenticated users to gain privileges via a modified JavaScript variable.

MEDIUM 4.9EPSS 0.61%

Does this matter?

Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.

Description

The web interface on Virtual Access GW6110A routers with software 9.00 before 9.09.27, 9.50 before 9.50.21, and 10.00 before 10.00.21 allows remote authenticated users to gain privileges via a modified JavaScript variable.

CVSS 2.0
4.9 MEDIUMAV:A/AC:M/Au:S/C:P/I:P/A:P
EPSS
0.61% probability · 47th percentile
CISA KEV
Not listed
Affected
virtualaccess/gw6110a firmware · virtualaccess/gw6110a
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.