4
CVSSv2

CVE-2014-3349

Published: 29/08/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in Cisco Intelligent Automation for Cloud could allow an authenticated, remote malicious user to upload arbitrary files. The vulnerability is due to insufficient input validation of a file type. An attacker could exploit this vulnerability by submitting a crafted file to an affected device. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement may reduce the likelihood of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco cloud portal -

Vendor Advisories

A vulnerability in Cisco Intelligent Automation for Cloud could allow an authenticated, remote attacker to upload arbitrary files The vulnerability is due to insufficient input validation of a file type An attacker could exploit this vulnerability by submitting a crafted file to an affected device Cisco has confirmed the vulnerability in a sec ...