CVE-2014-7994
Last modified
CVE-2014-7994 is a vulnerability of currently unknown severity. Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to an unspecified HTTP handler on the local network, aka Cisco-Meraki defect ID 00301991.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to an unspecified HTTP handler on the local network, aka Cisco-Meraki defect ID 00301991.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Meraki Mr Firmware | <= 2014-09-24 |
| Cisco | Meraki Mr | All versions |
| Cisco | Meraki Mx Firmware | <= 2014-09-24 |
| Cisco | Meraki Mx | All versions |
| Cisco | Meraki Ms Firmware | <= 2014-09-24 |
| Cisco | Meraki Ms | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-7994?
How severe is CVE-2014-7994?
How do I fix CVE-2014-7994?
Are you affected by CVE-2014-7994?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
