9.7
CVSSv2

CVE-2014-2046

Published: 14/05/2014 Updated: 14/05/2014
CVSS v2 Base Score: 9.7 | Impact Score: 9.5 | Exploitability Score: 10
VMScore: 975
Vector: AV:N/AC:L/Au:N/C:P/I:C/A:C

Vulnerability Summary

cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote malicious users to (1) obtain credentials and other sensitive information via a certain request to the config.getValuesHashExcludePaths method or (2) modify the firmware via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

broadcom pipa_c211_web_interface 1.1

broadcom pipa_c211 -

Exploits

Vulnerability title: Unauthenticated Credential And Configuration Retrieval In Broadcom Ltd PIPA C211 CVE: CVE-2014-2046 Vendor: Broadcom Ltd Product: PIPA C211 Affected version: Soft Rev: SR11, HW Rev: PIPA C211 rev2 Fixed version: N/A Reported by: Jerzy Kramarz Details: By sending the following request to the BROADCOM PIPA C211 web interface i ...
Broadcom PIPA C211 suffers from credential and information disclosure vulnerabilities ...