CVE-2014-0659
Last modified
CVE-2014-0659 is a vulnerability of currently unknown severity. The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.. EPSS estimates a 73.83% chance of exploitation in the next 30 days.
Description
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Rvs4000 Firmware | <= 2.0.3.2 |
| Cisco | Rvs4000 Firmware | 1.3.2.0 |
| Cisco | Rvs4000 Firmware | 1.3.3.5 |
| Cisco | Rvs4000 Firmware | 2.0.0.3 |
| Cisco | Rvs4000 Firmware | 2.0.2.7 |
| Cisco | Rvs4000 | All versions |
| Cisco | Wrvs4400n Firmware | 1.1.03 |
| Cisco | Wrvs4400n Firmware | 1.1.13 |
| Cisco | Wrvs4400n Firmware | 2.0.1.3 |
| Cisco | Wrvs4400n Firmware | 2.0.2.1 |
| Cisco | Wrvs4400n | All versions |
| Cisco | Wap4410n Firmware | <= 2.0.6.1 |
| Cisco | Wap4410n Firmware | 2.0.2.1 |
| Cisco | Wap4410n Firmware | 2.0.3.3 |
| Cisco | Wap4410n Firmware | 2.0.4.2 |
| Cisco | Wap4410n | All versions |
References
- http://www.securityfocus.com/bid/64776Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029579Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029580Third Party Advisory, VDB Entry
- https://github.com/elvanderb/TCP-32764Issue Tracking, Patch
- http://www.securityfocus.com/bid/64776Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029579Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029580Third Party Advisory, VDB Entry
- https://github.com/elvanderb/TCP-32764Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0659?
How severe is CVE-2014-0659?
How do I fix CVE-2014-0659?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-0653The Identity Firewall (IDFW) functionality in Cisco Adaptive…
- CVE-2014-0654Cisco Context Directory Agent (CDA) allows remote attackers …
- CVE-2014-0655The Identity Firewall (IDFW) functionality in Cisco Adaptive…
- CVE-2014-0656Cisco Context Directory Agent (CDA) allows remote authentica…
- CVE-2014-0657The administration portal in Cisco Unified Communications Ma…
- CVE-2014-0658Cisco 9900 Unified IP phones allow remote attackers to cause…
- CVE-2014-0660Cisco TelePresence ISDN Gateway with software before 2.2(1.9…
- CVE-2014-0661The System Status Collection Daemon (SSCD) in Cisco TelePres…
- CVE-2014-0662The SIP module in Cisco TelePresence Video Communication Ser…
- CVE-2014-0663Cross-site scripting (XSS) vulnerability in the web framewor…
- CVE-2014-0664The server in Cisco Unity Connection allows remote authentic…
- CVE-2014-0665The RBAC implementation in Cisco Identity Services Engine (I…
Are you affected by CVE-2014-0659?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
