{"api_version":"1","generated_at":"2026-07-23T07:10:03+00:00","cve":"CVE-2014-9193","urls":{"html":"https://cve.report/CVE-2014-9193","api":"https://cve.report/api/cve/CVE-2014-9193.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-9193","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-9193"},"summary":{"title":"Innominate mGuard Improper Privilege Management","description":"Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting.","state":"PUBLISHED","assigner":"icscert","published_at":"2014-12-20 00:59:03","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-269","CWE-264","CWE-269 CWE-269"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9","severity":"","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}},{"version":"2.0","source":"ics-cert@hq.dhs.gov","type":"Secondary","score":"8.5","severity":"","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}},{"version":"2.0","source":"CNA","type":"CVSS","score":"8.5","severity":"","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","data":{"accessComplexity":"MEDIUM","accessVector":"NETWORK","authentication":"SINGLE","availabilityImpact":"COMPLETE","baseScore":8.5,"confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","version":"2.0"}}],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-14-352-02","name":"https://ics-cert.us-cert.gov/advisories/ICSA-14-352-02","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Innominate mGuard Privilege Escalation Vulnerability | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.innominate.com/data/downloads/software/innominate_security_advisory_20141217_001_en.pdf","name":"http://www.innominate.com/data/downloads/software/innominate_security_advisory_20141217_001_en.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PHOENIX CONTACT | PHOENIX CONTACT Cyber Security GmbH","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-352-02","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-352-02","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-9193","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-9193","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Innominate","product":"mGuard","version":"affected 8.1.3 custom","platforms":[]},{"source":"CNA","vendor":"Innominate","product":"mGuard","version":"unaffected 7.6.6","platforms":[]},{"source":"CNA","vendor":"Innominate","product":"mGuard","version":"unaffected 8.1.4","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Innominate has released firmware patches Version 7.6.6 and Version \n8.1.4 that mitigates the vulnerability in the mGuard firmware Version 7 \nand Version 8, respectively. Innominate recommends that customers using \nfirmware versions older than Version 7, which are no longer being \nmaintained, should upgrade to mGuard firmware Version 7.6.6 or Version \n8.1.4. Innominate also recommends that customers limit access to the \nadministrative interfaces to a minimum via firewall rules.\n\n\nFor additional information on the vulnerability, Innominate’s security advisory is available on its web site at:\n\n http://www.innominate.com/en/downloads/security-advisories \n\n\nInnominate’s firmware updates are available on its web site at:\n\n http://www.innominate.com/en/downloads/updates","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Innominate Security Technologies has identified a privilege escalation vulnerability affecting all mGuard devices.","lang":"en"}],"nvd_cpes":[{"cve_year":"2014","cve_id":"9193","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"innominate","cpe5":"mguard_firmware","cpe6":"8.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9193","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"innominate","cpe5":"mguard_firmware","cpe6":"8.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9193","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"innominate","cpe5":"mguard_firmware","cpe6":"8.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9193","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"innominate","cpe5":"mguard_firmware","cpe6":"8.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9193","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"innominate","cpe5":"mguard_firmware","cpe6":"8.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9193","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"innominate","cpe5":"mguard_firmware","cpe6":"8.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9193","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"innominate","cpe5":"mguard_firmware","cpe6":"8.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9193","vulnerable":"1","versionEndIncluding":"7.6.6","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"innominate","cpe5":"mguard_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2014-9193","qid":"591069","title":"Phoenix Contact Innominate mGuard devices Vulnerability (Security Advisory 2014/12/17-001)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T13:40:24.558Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.innominate.com/data/downloads/software/innominate_security_advisory_20141217_001_en.pdf"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-14-352-02"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"mGuard","vendor":"Innominate","versions":[{"lessThanOrEqual":"8.1.3","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"7.6.6"},{"status":"unaffected","version":"8.1.4"}]}],"credits":[{"lang":"en","type":"finder","value":"Innominate Security Technologies has identified a privilege escalation vulnerability affecting all mGuard devices."}],"datePublic":"2014-12-17T07:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting.</p>"}],"value":"Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting."}],"metrics":[{"cvssV2_0":{"accessComplexity":"MEDIUM","accessVector":"NETWORK","authentication":"SINGLE","availabilityImpact":"COMPLETE","baseScore":8.5,"confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","version":"2.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-269","description":"CWE-269","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-07-28T20:35:16.302Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.innominate.com/data/downloads/software/innominate_security_advisory_20141217_001_en.pdf"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-352-02"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Innominate has released firmware patches Version 7.6.6 and Version \n8.1.4 that mitigates the vulnerability in the mGuard firmware Version 7 \nand Version 8, respectively. Innominate recommends that customers using \nfirmware versions older than Version 7, which are no longer being \nmaintained, should upgrade to mGuard firmware Version 7.6.6 or Version \n8.1.4. Innominate also recommends that customers limit access to the \nadministrative interfaces to a minimum via firewall rules.</p>\n<p>For additional information on the vulnerability, Innominate’s security advisory is available on its web site at:</p><p><a target=\"_blank\" rel=\"nofollow\" href=\"http://www.innominate.com/en/downloads/security-advisories\">http://www.innominate.com/en/downloads/security-advisories</a></p>\n<p>Innominate’s firmware updates are available on its web site at:</p><p><a target=\"_blank\" rel=\"nofollow\" href=\"http://www.innominate.com/en/downloads/updates\">http://www.innominate.com/en/downloads/updates</a>&nbsp;&nbsp;<br></p>"}],"value":"Innominate has released firmware patches Version 7.6.6 and Version \n8.1.4 that mitigates the vulnerability in the mGuard firmware Version 7 \nand Version 8, respectively. Innominate recommends that customers using \nfirmware versions older than Version 7, which are no longer being \nmaintained, should upgrade to mGuard firmware Version 7.6.6 or Version \n8.1.4. Innominate also recommends that customers limit access to the \nadministrative interfaces to a minimum via firewall rules.\n\n\nFor additional information on the vulnerability, Innominate’s security advisory is available on its web site at:\n\n http://www.innominate.com/en/downloads/security-advisories \n\n\nInnominate’s firmware updates are available on its web site at:\n\n http://www.innominate.com/en/downloads/updates"}],"source":{"advisory":"ICSA-14-352-02","discovery":"INTERNAL"},"title":"Innominate mGuard Improper Privilege Management","x_generator":{"engine":"Vulnogram 0.2.0"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2014-9193","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.innominate.com/data/downloads/software/innominate_security_advisory_20141217_001_en.pdf","refsource":"CONFIRM","url":"http://www.innominate.com/data/downloads/software/innominate_security_advisory_20141217_001_en.pdf"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-14-352-02","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-14-352-02"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2014-9193","datePublished":"2014-12-20T00:00:00.000Z","dateReserved":"2014-12-02T00:00:00.000Z","dateUpdated":"2025-07-28T20:35:16.302Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-12-20 00:59:03","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-269","CWE-264","CWE-269 CWE-269"],"metrics":{"cvssMetricV2":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:innominate:mguard_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"7.6.6","matchCriteriaId":"8AEF887D-FBFD-4EC4-BAF4-9BE80EDEAF6D"},{"vulnerable":true,"criteria":"cpe:2.3:o:innominate:mguard_firmware:8.0.0:*:*:*:*:*:*:*","matchCriteriaId":"4A14A9C8-D4E3-45F4-B1F8-F9D93F48506A"},{"vulnerable":true,"criteria":"cpe:2.3:o:innominate:mguard_firmware:8.0.1:*:*:*:*:*:*:*","matchCriteriaId":"5055C2CB-9D8A-4490-90EC-C32C019E756F"},{"vulnerable":true,"criteria":"cpe:2.3:o:innominate:mguard_firmware:8.0.2:*:*:*:*:*:*:*","matchCriteriaId":"1080DE53-1831-4BD4-9084-5ADB6886526C"},{"vulnerable":true,"criteria":"cpe:2.3:o:innominate:mguard_firmware:8.0.3:*:*:*:*:*:*:*","matchCriteriaId":"81F1A071-7FA9-4317-A4E1-D05150587F51"},{"vulnerable":true,"criteria":"cpe:2.3:o:innominate:mguard_firmware:8.1.1:*:*:*:*:*:*:*","matchCriteriaId":"F59B18C5-4164-454E-907D-7B5D0DAC0675"},{"vulnerable":true,"criteria":"cpe:2.3:o:innominate:mguard_firmware:8.1.2:*:*:*:*:*:*:*","matchCriteriaId":"C0B52E63-9C7E-41F9-B268-3EF905F89C27"},{"vulnerable":true,"criteria":"cpe:2.3:o:innominate:mguard_firmware:8.1.3:*:*:*:*:*:*:*","matchCriteriaId":"F42DC442-074D-4223-9FD2-2B010E004255"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"9193","Ordinal":"1","Title":"Innominate mGuard Improper Privilege Management","CVE":"CVE-2014-9193","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"9193","Ordinal":"1","NoteData":"Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting.","Type":"Description","Title":"Innominate mGuard Improper Privilege Management"},{"CveYear":"2014","CveId":"9193","Ordinal":"2","NoteData":"2014-12-19","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"9193","Ordinal":"3","NoteData":"2014-12-19","Type":"Other","Title":"Modified"}]}}}