Vulnerability Description
A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions is possible. Firewalling or disabling the service is recommended.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cardosystems | Scala Rider Q3 Firmware | - |
| Cardosystems | Scala Rider Q3 | - |
Related Weaknesses (CWE)
References
- http://www.remote-exploit.org/archives/2014/06/03/ride_with_the_devil/ExploitThird Party Advisory
- https://vuldb.com/?id.13428Third Party Advisory
- http://www.remote-exploit.org/archives/2014/06/03/ride_with_the_devil/ExploitThird Party Advisory
- https://vuldb.com/?id.13428Third Party Advisory
FAQ
What is CVE-2014-125001?
CVE-2014-125001 is a vulnerability with a CVSS score of 8.1 (HIGH). A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions...
How severe is CVE-2014-125001?
CVE-2014-125001 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-125001?
Check the references section above for vendor advisories and patch information. Affected products include: Cardosystems Scala Rider Q3 Firmware, Cardosystems Scala Rider Q3.