CVE-2014-0659
Last modified
CVE-2014-0659 is a vulnerability of currently unknown severity. The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.. EPSS estimates a 73.83% chance of exploitation in the next 30 days.
Description
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Rvs4000 Firmware | <= 2.0.3.2 |
| Cisco | Rvs4000 Firmware | 1.3.2.0 |
| Cisco | Rvs4000 Firmware | 1.3.3.5 |
| Cisco | Rvs4000 Firmware | 2.0.0.3 |
| Cisco | Rvs4000 Firmware | 2.0.2.7 |
| Cisco | Rvs4000 | All versions |
| Cisco | Wrvs4400n Firmware | 1.1.03 |
| Cisco | Wrvs4400n Firmware | 1.1.13 |
| Cisco | Wrvs4400n Firmware | 2.0.1.3 |
| Cisco | Wrvs4400n Firmware | 2.0.2.1 |
| Cisco | Wrvs4400n | All versions |
| Cisco | Wap4410n Firmware | <= 2.0.6.1 |
| Cisco | Wap4410n Firmware | 2.0.2.1 |
| Cisco | Wap4410n Firmware | 2.0.3.3 |
| Cisco | Wap4410n Firmware | 2.0.4.2 |
| Cisco | Wap4410n | All versions |
References
- http://www.securityfocus.com/bid/64776Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029579Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029580Third Party Advisory, VDB Entry
- https://github.com/elvanderb/TCP-32764Issue Tracking, Patch
- http://www.securityfocus.com/bid/64776Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029579Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029580Third Party Advisory, VDB Entry
- https://github.com/elvanderb/TCP-32764Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0659?
How severe is CVE-2014-0659?
How do I fix CVE-2014-0659?
Are you affected by CVE-2014-0659?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
