Vulnerability Description
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Rvs4000 Firmware | <= 2.0.3.2 |
| Cisco | Rvs4000 | - |
| Cisco | Wrvs4400N Firmware | 1.1.03 |
| Cisco | Wrvs4400N | - |
| Cisco | Wap4410N Firmware | <= 2.0.6.1 |
| Cisco | Wap4410N | - |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/56292
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32381Vendor Advisory
- http://www.securityfocus.com/bid/64776Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1029579Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1029580Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90233
- https://github.com/elvanderb/TCP-32764Issue TrackingPatch
- http://secunia.com/advisories/56292
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32381Vendor Advisory
- http://www.securityfocus.com/bid/64776Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1029579Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1029580Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90233
FAQ
What is CVE-2014-0659?
CVE-2014-0659 is a vulnerability with a CVSS score of 10.0 (HIGH). The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote ...
How severe is CVE-2014-0659?
CVE-2014-0659 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0659?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Rvs4000 Firmware, Cisco Rvs4000, Cisco Wrvs4400N Firmware, Cisco Wrvs4400N, Cisco Wap4410N Firmware.