Cisco Adaptive Security Appliance Software CVE-2014-3391 Local Privilege Escalation Vulnerability
BID:70300
Info
Cisco Adaptive Security Appliance Software CVE-2014-3391 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 70300 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3391 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 08 2014 12:00AM |
| Updated: | Oct 08 2014 12:00AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Adaptive Security Appliance Software CVE-2014-3391 Local Privilege Escalation Vulnerability
Cisco Adaptive Security Appliance (ASA) Software is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to inject a malicious library and take complete control of the system.
This issue is being tracked by Cisco Bug ID CSCtq52661.
Cisco Adaptive Security Appliance (ASA) Software is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to inject a malicious library and take complete control of the system.
This issue is being tracked by Cisco Bug ID CSCtq52661.
Exploit / POC
Cisco Adaptive Security Appliance Software CVE-2014-3391 Local Privilege Escalation Vulnerability
An attacker uses readily available tools to exploit the issue.
An attacker uses readily available tools to exploit the issue.
Solution / Fix
Cisco Adaptive Security Appliance Software CVE-2014-3391 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.