Cisco Adaptive Security Appliance Software CVE-2014-3390 Local Privilege Escalation Vulnerability
BID:70296
Info
Cisco Adaptive Security Appliance Software CVE-2014-3390 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 70296 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3390 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 08 2014 12:00AM |
| Updated: | Oct 08 2014 12:00AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Adaptive Security Appliance Software CVE-2014-3390 Local Privilege Escalation Vulnerability
Cisco Adaptive Security Appliance (ASA) Software is prone to a local privilege-escalation vulnerability because it fails to sufficiently sanitize the user-supplied input.
A local attacker can exploit this issue to gain root privileges.
This issue is being tracked by Cisco Bug IDs CSCuq41510 and CSCuq47574.
Cisco Adaptive Security Appliance (ASA) Software is prone to a local privilege-escalation vulnerability because it fails to sufficiently sanitize the user-supplied input.
A local attacker can exploit this issue to gain root privileges.
This issue is being tracked by Cisco Bug IDs CSCuq41510 and CSCuq47574.
Exploit / POC
Cisco Adaptive Security Appliance Software CVE-2014-3390 Local Privilege Escalation Vulnerability
An attacker uses readily available tools to exploit the issue.
An attacker uses readily available tools to exploit the issue.
Solution / Fix
Cisco Adaptive Security Appliance Software CVE-2014-3390 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Adaptive Security Appliance Software CVE-2014-3390 Local Privilege Escalation Vulnerability
References:
References: