{"api_version":"1","generated_at":"2026-07-23T08:12:57+00:00","cve":"CVE-2014-2378","urls":{"html":"https://cve.report/CVE-2014-2378","api":"https://cve.report/api/cve/CVE-2014-2378.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-2378","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-2378"},"summary":{"title":"Sensys Networks Traffic Sensor Download of Code Without Integrity Check","description":"Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update.","state":"PUBLISHED","assigner":"icscert","published_at":"2014-09-05 17:55:06","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-494","CWE-94","CWE-494 CWE-494"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.6","severity":"","vector":"AV:A/AC:M/Au:N/C:C/I:C/A:P","data":{"version":"2.0","vectorString":"AV:A/AC:M/Au:N/C:C/I:C/A:P","baseScore":7.6,"accessVector":"ADJACENT_NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"PARTIAL"}},{"version":"2.0","source":"ics-cert@hq.dhs.gov","type":"Secondary","score":"6.5","severity":"","vector":"AV:A/AC:H/Au:N/C:C/I:C/A:P","data":{"version":"2.0","vectorString":"AV:A/AC:H/Au:N/C:C/I:C/A:P","baseScore":6.5,"accessVector":"ADJACENT_NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"PARTIAL"}},{"version":"2.0","source":"CNA","type":"CVSS","score":"6.5","severity":"","vector":"AV:A/AC:H/Au:N/C:C/I:C/A:P","data":{"accessComplexity":"HIGH","accessVector":"ADJACENT_NETWORK","authentication":"NONE","availabilityImpact":"PARTIAL","baseScore":6.5,"confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","vectorString":"AV:A/AC:H/Au:N/C:C/I:C/A:P","version":"2.0"}}],"references":[{"url":"http://www.sensysnetworks.com/distributors/","name":"http://www.sensysnetworks.com/distributors/","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-14-247-01","name":"https://ics-cert.us-cert.gov/advisories/ICSA-14-247-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"Sensys Networks Traffic Sensor Vulnerabilities (Update A) | ICS-CERT","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-247-01a","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-247-01a","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.sensysnetworks.com/resources-by-category/#sw","name":"http://www.sensysnetworks.com/resources-by-category/#sw","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-2378","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2378","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Sensys Networks","product":"VSN240-F","version":"affected VDS 2.10.1 custom","platforms":[]},{"source":"CNA","vendor":"Sensys Networks","product":"VSN240-F","version":"affected VDS 1.8.8 custom","platforms":[]},{"source":"CNA","vendor":"Sensys Networks","product":"VSN240-F","version":"affected TrafficDOT 2.10.3 custom","platforms":[]},{"source":"CNA","vendor":"Sensys Networks","product":"VSN240-T","version":"affected VDS 2.10.1 custom","platforms":[]},{"source":"CNA","vendor":"Sensys Networks","product":"VSN240-T","version":"affected VDS 1.8.8 custom","platforms":[]},{"source":"CNA","vendor":"Sensys Networks","product":"VSN240-T","version":"affected TrafficDOT 2.10.3 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Sensys Networks has produced updated product versions VDS 2.10.1 and \nTrafficDOT 2.10.3 to remediate vulnerabilities identified in their \nVSN240-F and VSN240-T traffic sensors.\n\n\n\n\nSensys Networks has released software update VDS 1.8.8, for an older \nmodel access point, to remediate traffic sensor vulnerabilities.\n\n\nThe updated human-machine interface version, TrafficDOT 2.10.3, \nenables encrypted software downloads for sensors and sensor data \nauthentication for access points and access point controller cards using\n updated versions VDS 2.10.1 or VDS 1.8.8.\n\n\n\n\nAdditional information about Sensys Networks’ software releases can be found at the following location:\n\n\n http://www.sensysnetworks.com/resources-by-category/#sw \n\nUpdated\n product versions are available through Sensys Networks’ local \ndistributors. Contact information for their local distributors can be \nfound at the following location:\n\n\n http://www.sensysnetworks.com/distributors/","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Cesar Cerrudo of IOActive","lang":"en"}],"nvd_cpes":[{"cve_year":"2014","cve_id":"2378","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensysnetworks","cpe5":"trafficdot","cpe6":"2.10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2378","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensysnetworks","cpe5":"trafficdot","cpe6":"2.10.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2378","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensysnetworks","cpe5":"trafficdot","cpe6":"2.8.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2378","vulnerable":"1","versionEndIncluding":"2.10.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensysnetworks","cpe5":"trafficdot","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2378","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensysnetworks","cpe5":"vds","cpe6":"1.8.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2378","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensysnetworks","cpe5":"vds","cpe6":"1.8.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2378","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensysnetworks","cpe5":"vds","cpe6":"2.6.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2378","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensysnetworks","cpe5":"vds","cpe6":"2.6.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2378","vulnerable":"1","versionEndIncluding":"2.10.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensysnetworks","cpe5":"vds","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2378","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sensysnetworks","cpe5":"vsn240-f","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2378","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sensysnetworks","cpe5":"vsn240-t","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:14:25.782Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-14-247-01"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"VSN240-F","vendor":"Sensys Networks","versions":[{"lessThan":"VDS 2.10.1","status":"affected","version":"0","versionType":"custom"},{"lessThan":"VDS 1.8.8","status":"affected","version":"0","versionType":"custom"},{"lessThan":"TrafficDOT 2.10.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"VSN240-T","vendor":"Sensys Networks","versions":[{"lessThan":"VDS 2.10.1","status":"affected","version":"0","versionType":"custom"},{"lessThan":"VDS 1.8.8","status":"affected","version":"0","versionType":"custom"},{"lessThan":"TrafficDOT 2.10.3","status":"affected","version":"0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Cesar Cerrudo of IOActive"}],"datePublic":"2014-09-04T06:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update.</p>"}],"value":"Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update."}],"metrics":[{"cvssV2_0":{"accessComplexity":"HIGH","accessVector":"ADJACENT_NETWORK","authentication":"NONE","availabilityImpact":"PARTIAL","baseScore":6.5,"confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","vectorString":"AV:A/AC:H/Au:N/C:C/I:C/A:P","version":"2.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-494","description":"CWE-494","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-13T23:00:45.632Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-247-01a"},{"url":"http://www.sensysnetworks.com/resources-by-category/#sw"},{"url":"http://www.sensysnetworks.com/distributors/"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Sensys Networks has produced updated product versions VDS 2.10.1 and \nTrafficDOT 2.10.3 to remediate vulnerabilities identified in their \nVSN240-F and VSN240-T traffic sensors.<br></p>\n\n<p>Sensys Networks has released software update VDS 1.8.8, for an older \nmodel access point, to remediate traffic sensor vulnerabilities.</p>\n<p>The updated human-machine interface version, TrafficDOT 2.10.3, \nenables encrypted software downloads for sensors and sensor data \nauthentication for access points and access point controller cards using\n updated versions VDS 2.10.1 or VDS 1.8.8.<br></p>\n\n<p>Additional information about Sensys Networks’ software releases can be found at the following location:</p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"http://www.sensysnetworks.com/resources-by-category/#sw\">http://www.sensysnetworks.com/resources-by-category/#sw</a></p><p>Updated\n product versions are available through Sensys Networks’ local \ndistributors. Contact information for their local distributors can be \nfound at the following location:</p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"http://www.sensysnetworks.com/distributors/\">http://www.sensysnetworks.com/distributors/</a></p>\n\n<br>"}],"value":"Sensys Networks has produced updated product versions VDS 2.10.1 and \nTrafficDOT 2.10.3 to remediate vulnerabilities identified in their \nVSN240-F and VSN240-T traffic sensors.\n\n\n\n\nSensys Networks has released software update VDS 1.8.8, for an older \nmodel access point, to remediate traffic sensor vulnerabilities.\n\n\nThe updated human-machine interface version, TrafficDOT 2.10.3, \nenables encrypted software downloads for sensors and sensor data \nauthentication for access points and access point controller cards using\n updated versions VDS 2.10.1 or VDS 1.8.8.\n\n\n\n\nAdditional information about Sensys Networks’ software releases can be found at the following location:\n\n\n http://www.sensysnetworks.com/resources-by-category/#sw \n\nUpdated\n product versions are available through Sensys Networks’ local \ndistributors. Contact information for their local distributors can be \nfound at the following location:\n\n\n http://www.sensysnetworks.com/distributors/"}],"source":{"advisory":"ICSA-14-247-01","discovery":"EXTERNAL"},"title":"Sensys Networks Traffic Sensor Download of Code Without Integrity Check","x_generator":{"engine":"Vulnogram 0.2.0"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2014-2378","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-14-247-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-14-247-01"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2014-2378","datePublished":"2014-09-05T17:00:00.000Z","dateReserved":"2014-03-13T00:00:00.000Z","dateUpdated":"2025-10-13T23:00:45.632Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-09-05 17:55:06","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-494","CWE-94","CWE-494 CWE-494"],"metrics":{"cvssMetricV2":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:H/Au:N/C:C/I:C/A:P","baseScore":6.5,"accessVector":"ADJACENT_NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.2,"impactScore":9.5,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:M/Au:N/C:C/I:C/A:P","baseScore":7.6,"accessVector":"ADJACENT_NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":5.5,"impactScore":9.5,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sensysnetworks:trafficdot:*:*:*:*:*:*:*:*","versionEndIncluding":"2.10.2","matchCriteriaId":"3DDAF38B-AE0B-4DF3-923B-92715D3D10E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:sensysnetworks:trafficdot:2.8.3:*:*:*:*:*:*:*","matchCriteriaId":"9D4CD91C-4002-4A30-B533-14CBF1B045CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:sensysnetworks:trafficdot:2.10.0:*:*:*:*:*:*:*","matchCriteriaId":"C685D52A-A97B-4DB7-AE66-F0FFAAAA5B4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:sensysnetworks:trafficdot:2.10.1:*:*:*:*:*:*:*","matchCriteriaId":"26D5EDCE-D7EC-45E8-8089-ED120E664E0C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:sensysnetworks:vsn240-f:-:*:*:*:*:*:*:*","matchCriteriaId":"EBE6EDF8-061E-4390-A09F-8C2D50951C4F"},{"vulnerable":true,"criteria":"cpe:2.3:h:sensysnetworks:vsn240-t:-:*:*:*:*:*:*:*","matchCriteriaId":"042983FF-7F9D-4A6D-8505-23C2AF8FE7BA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sensysnetworks:vds:*:*:*:*:*:*:*:*","versionEndIncluding":"2.10.0","matchCriteriaId":"3EACF484-ADB9-491C-A176-5860345A1E02"},{"vulnerable":true,"criteria":"cpe:2.3:a:sensysnetworks:vds:1.8.5:*:*:*:*:*:*:*","matchCriteriaId":"525BAF30-197B-4EF1-8E2E-358240EDB90B"},{"vulnerable":true,"criteria":"cpe:2.3:a:sensysnetworks:vds:1.8.7:*:*:*:*:*:*:*","matchCriteriaId":"ED1A73FC-7A8C-47B0-BD16-7DBF39F28295"},{"vulnerable":true,"criteria":"cpe:2.3:a:sensysnetworks:vds:2.6.3:*:*:*:*:*:*:*","matchCriteriaId":"05B792D3-A6EE-46E6-A461-10ADD327B9C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:sensysnetworks:vds:2.6.4:*:*:*:*:*:*:*","matchCriteriaId":"E008BB72-F728-4293-9BF0-287572688DDE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:sensysnetworks:vsn240-f:-:*:*:*:*:*:*:*","matchCriteriaId":"EBE6EDF8-061E-4390-A09F-8C2D50951C4F"},{"vulnerable":true,"criteria":"cpe:2.3:h:sensysnetworks:vsn240-t:-:*:*:*:*:*:*:*","matchCriteriaId":"042983FF-7F9D-4A6D-8505-23C2AF8FE7BA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"2378","Ordinal":"1","Title":"Sensys Networks Traffic Sensor Download of Code Without Integrit","CVE":"CVE-2014-2378","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"2378","Ordinal":"1","NoteData":"Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update.","Type":"Description","Title":"Sensys Networks Traffic Sensor Download of Code Without Integrit"},{"CveYear":"2014","CveId":"2378","Ordinal":"2","NoteData":"2014-09-05","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"2378","Ordinal":"3","NoteData":"2014-09-05","Type":"Other","Title":"Modified"}]}}}