CVE-2014-5502
The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) ccc_flush_sql_file opcode.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) ccc_flush_sql_file opcode.
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 2.32% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- cyberoam/cyberoam os
- Source
- cve@mitre.org
References
- http://kb.cyberoam.com/default.asp?id=3049Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-14-328/
- http://www.zerodayinitiative.com/advisories/ZDI-14-331/
- http://www.zerodayinitiative.com/advisories/ZDI-14-332/
- http://www.zerodayinitiative.com/advisories/ZDI-14-333/
- http://kb.cyberoam.com/default.asp?id=3049Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-14-328/
- http://www.zerodayinitiative.com/advisories/ZDI-14-331/
- http://www.zerodayinitiative.com/advisories/ZDI-14-332/
- http://www.zerodayinitiative.com/advisories/ZDI-14-333/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.