CVE-2014-8003
published 2014-12-10CVE-2014-8003: Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows local users to obtain shell access via a crafted map-nfs…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.37%
29.7th percentile
Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows local users to obtain shell access via a crafted map-nfs command, aka Bug ID CSCup05998.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_computing_system | <= 2.2\(2c\)a | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Integrated Management Controller Privilege Escalation Vulnerability
vendor_cisco·2014-12-01·CVSS 7.2
CVE-2014-8003 [HIGH] CWE-20 Cisco Integrated Management Controller Privilege Escalation Vulnerability
Cisco Integrated Management Controller Privilege Escalation Vulnerability
Cisco Integrated Management Controller contains a vulnerability that could allow an authenticated, local attacker to gain shell-level access to the affected device.
The vulnerability is due to improper input validation in the map-nfs command. An attacker could exploit this vulnerability by sending crafted commands in the command-line interface of the affected device.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker must authenticate and have local access to the targeted device. These access requirements decrease the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit
Citrix
CVE-2014-8580 - Authentication Flaw in Citrix NetScaler Application Delivery Controller and NetScaler Gateway Could Result in Unauthorised Access to Network Resources
vendor_citrix·CVSS 4.9
CVE-2014-8580 [MEDIUM] CVE-2014-8580 - Authentication Flaw in Citrix NetScaler Application Delivery Controller and NetScaler Gateway Could Result in Unauthorised Access to Network Resources
CVE-2014-8580 - Authentication Flaw in Citrix NetScaler Application Delivery Controller and NetScaler Gateway Could Result in Unauthorised Access to Network Resources
of Problem An authentication flaw has been identified in certain configurations of Citrix NetScaler ADC and NetScaler Gateway that could allow an authenticated user to obtain unauthorised access to network resources for another authenticated user. This flaw affects the following versions of Citrix NetScaler ADC and NetScaler Gateway: Version 10.5.x between 10.5.50.10 and 10.5.51.10 Version 10.1.x between 10.1.122.17 and 10.1.128.8 Version 10.1.x “Enhanced” between 10.1-120.1316.e and 10.1-128.8003.e This flaw has been assigned the following CVE number: CVE-2014-8580: Authentication Flaw in Citrix NetScaler Application Delive
GHSA
GHSA-r55p-5gm9-gq67: Cisco Integrated Management Controller in Cisco Unified Computing System 2
ghsa_unreviewed·2022-05-17
CVE-2014-8003 [HIGH] CWE-20 GHSA-r55p-5gm9-gq67: Cisco Integrated Management Controller in Cisco Unified Computing System 2
Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows local users to obtain shell access via a crafted map-nfs command, aka Bug ID CSCup05998.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-12-10
Published