CVE-2014-2195
Published May 20, 2014
Last updated 6 years ago
Overview
- Description
- Cisco AsyncOS on Email Security Appliance (ESA) and Content Security Management Appliance (SMA) devices, when Active Directory is enabled, does not properly handle group names, which allows remote attackers to gain role privileges by leveraging group-name similarity, aka Bug ID CSCum86085.
- Source
- ykramarz@cisco.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:cisco:asyncos:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "87AA6AB8-12B9-4810-9D06-01EEBF7B01C9" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:cisco:content_security_management_appliance:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "60635EC8-9AFA-400D-A919-66E60CDEF852" }, { "criteria": "cpe:2.3:o:cisco:email_security_appliance_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5BA3A518-E103-4D98-A040-88ED4E0D73CC" } ], "operator": "OR" } ], "operator": "AND" } ]