CVE-2014-0684
published 2014-05-07CVE-2014-0684: Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug ID CSCui56136.
PriorityP416medium4.6CVSS 2.0
AVLACLAuSCNINAC
EPSS
0.30%
22.3th percentile
Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug ID CSCui56136.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:S/C:N/I:N/A:C
vendor_cisco4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus 7000 Denial of Service Vulnerability
vendor_cisco·2014-05-06·CVSS 4.6
CVE-2014-0684 [MEDIUM] CWE-20 Cisco Nexus 7000 Denial of Service Vulnerability
Cisco Nexus 7000 Denial of Service Vulnerability
A vulnerability in Cisco Nexus 7000 Series Switches could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to an error in input validation for the sed command. An attacker could exploit this vulnerability by passing crafted input to the sed command. An exploit could allow the attacker to cause a DoS condition.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker would need local access to the targeted device. This access requirement reduces the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is
GHSA
GHSA-4fq6-7734-x384: Cisco NX-OS 6
ghsa_unreviewed·2022-05-17
CVE-2014-0684 [MEDIUM] CWE-20 GHSA-4fq6-7734-x384: Cisco NX-OS 6
Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug ID CSCui56136.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-05-07
Published