Lucene search

K
cveCiscoCVE-2014-2119
HistoryMar 21, 2014 - 1:04 a.m.

CVE-2014-2119

2014-03-2101:04:02
CWE-264
cisco
web.nvd.nist.gov
28
cve-2014-2119
cisco
asyncos
email security appliance
content security management appliance
slbl
bug ids
cscug79377
cscug80118
ftp
security vulnerability

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.002

Percentile

57.1%

The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1-023 and Cisco Content Security Management Appliance (SMA) before 7.9.1-110 and 8.x before 8.1.1-013 allows remote authenticated users to execute arbitrary code with root privileges via an FTP session that uploads a modified SLBL database file, aka Bug IDs CSCug79377 and CSCug80118.

Affected configurations

Nvd
Node
ciscoironport_asyncosRange7.9.1-039
OR
ciscoironport_asyncosMatch8.0
OR
ciscoironport_asyncosMatch8.0.1
OR
ciscoironport_asyncosMatch8.1
AND
ciscocontent_security_management_applianceMatch-
Node
ciscoironport_asyncosRange7.6.2-201
OR
ciscoironport_asyncosMatch8.0
OR
ciscoironport_asyncosMatch8.0.1
AND
ciscoemail_security_appliance_firmwareMatch-
VendorProductVersionCPE
ciscoironport_asyncos*cpe:2.3:o:cisco:ironport_asyncos:*:*:*:*:*:*:*:*
ciscoironport_asyncos8.0cpe:2.3:o:cisco:ironport_asyncos:8.0:*:*:*:*:*:*:*
ciscoironport_asyncos8.0.1cpe:2.3:o:cisco:ironport_asyncos:8.0.1:*:*:*:*:*:*:*
ciscoironport_asyncos8.1cpe:2.3:o:cisco:ironport_asyncos:8.1:*:*:*:*:*:*:*
ciscocontent_security_management_appliance-cpe:2.3:h:cisco:content_security_management_appliance:-:*:*:*:*:*:*:*
ciscoemail_security_appliance_firmware-cpe:2.3:o:cisco:email_security_appliance_firmware:-:*:*:*:*:*:*:*

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.002

Percentile

57.1%