CVE-2014-0659
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 73.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 73.83% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- cisco/rvs4000 firmware · cisco/rvs4000 · cisco/wrvs4400n firmware · cisco/wrvs4400n · cisco/wap4410n firmware · cisco/wap4410n
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/56292
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140110-sbdVendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32381Vendor Advisory
- http://www.securityfocus.com/bid/64776Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029579Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029580Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90233
- https://github.com/elvanderb/TCP-32764Issue Tracking, Patch
- http://secunia.com/advisories/56292
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140110-sbdVendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32381Vendor Advisory
- http://www.securityfocus.com/bid/64776Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029579Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029580Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90233
- https://github.com/elvanderb/TCP-32764Issue Tracking, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.