CVE-2014-2196
published 2014-05-26CVE-2014-2196: Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allows remote SharePoint servers to execute…
PriorityP349critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.43%
82.3th percentile
Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allows remote SharePoint servers to execute arbitrary code via a malformed response, aka Bug ID CSCue18479.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Wide Area Application Services Remote Code Execution Vulnerability
vendor_cisco·2014-05-21·CVSS 9.3
CVE-2014-2196 [CRITICAL] CWE-119 Cisco Wide Area Application Services Remote Code Execution Vulnerability
Cisco Wide Area Application Services Remote Code Execution Vulnerability
A vulnerability in Cisco Wide Area Application Services (WAAS) software versions 5.1.1 through 5.1.1d, when configured with the SharePoint acceleration feature, could allow an unauthenticated, remote attacker to exploit a buffer overflow and cause arbitrary code execution.
The vulnerability is due to incorrect buffer handling for SharePoint responses. An attacker could exploit this vulnerability by convincing a user to access a malicious SharePoint application. An exploit could allow the attacker to crash the application optimization handler and execute arbitrary code with elevated privileges on the WAAS appliance.
Cisco has released software updates that address this vulnerability. This advisory is available at th
Cisco
Cisco Wide Area Application Services Remote Code Execution Vulnerability
vendor_cisco
CVE-2014-2196 Cisco Wide Area Application Services Remote Code Execution Vulnerability
CVE-2014-2196: Cisco Wide Area Application Services Remote Code Execution Vulnerability
A vulnerability in Cisco Wide Area Application Services (WAAS) software versions 5.1.1 through 5.1.1d, when configured with the SharePoint acceleration feature, could allow an unauthenticated, remote attacker to exploit a buffer overflow and cause arbitrary code execution. The vulnerability is due to incorrect buffer handling for SharePoint responses. An attacker could exploit this vulnerability by convincing a user to access a malicious SharePoint application. An exploit could allow the attacker to crash the application optimization handler and execute arbitrary code with elevated privileges on the WAAS appliance. Cisco has released software updates that address this vulnerability. This advisory is ava
GHSA
GHSA-84xf-fv65-wjp3: Cisco Wide Area Application Services (WAAS) 5
ghsa_unreviewed·2022-05-17
CVE-2014-2196 [HIGH] CWE-94 GHSA-84xf-fv65-wjp3: Cisco Wide Area Application Services (WAAS) 5
Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allows remote SharePoint servers to execute arbitrary code via a malformed response, aka Bug ID CSCue18479.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-05-26
Published