CVE-2014-7990
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/viewAlert.x?alertId=36351
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7990
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7990
- http://tools.cisco.com/security/center/viewAlert.x?alertId=36351
- http://www.securityfocus.com/bid/70968
- http://www.securitytracker.com/id/1031179
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98529
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7990
- http://tools.cisco.com/security/center/viewAlert.x?alertId=36351
- http://www.securityfocus.com/bid/70968
- http://www.securitytracker.com/id/1031179
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98529
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.