HIGH · 9.7

CVE-2014-2046

cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obtain credentials and other sensitive information via...

Vulnerability Description

cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obtain credentials and other sensitive information via a certain request to the config.getValuesHashExcludePaths method or (2) modify the firmware via unspecified vectors.

CVSS Score

9.7

HIGH

AV:N/AC:L/Au:N/C:P/I:C/A:C
Confidentiality
PARTIAL
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
BroadcomPipa C211 Web Interface1.1
BroadcomPipa C211-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-2046?

CVE-2014-2046 is a vulnerability with a CVSS score of 9.7 (HIGH). cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obtain credentials and other sensitive information via...

How severe is CVE-2014-2046?

CVE-2014-2046 has been rated HIGH with a CVSS base score of 9.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-2046?

Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Pipa C211 Web Interface, Broadcom Pipa C211.