6.8
CVSSv2

CVE-2014-3390

Published: 10/10/2014 Updated: 15/08/2023
CVSS v2 Base Score: 6.8 | Impact Score: 10 | Exploitability Score: 3.1
VMScore: 605
Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The Virtual Network Management Center (VNMC) policy implementation in Cisco ASA Software 8.7 prior to 8.7(1.14), 9.2 prior to 9.2(2.8), and 9.3 prior to 9.3(1.1) allows local users to obtain Linux root access by leveraging administrative privileges and executing a crafted script, aka Bug IDs CSCuq41510 and CSCuq47574.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive security appliance software 9.3.1.1

cisco adaptive security appliance software 9.3.1

cisco adaptive security appliance software 9.2.1

cisco adaptive security appliance software 9.2.2.4

cisco adaptive security appliance software 8.7.8

cisco adaptive security appliance software 9.2.2

cisco adaptive security appliance software 8.7.1.4

cisco adaptive security appliance software 8.7.1.7

cisco adaptive security appliance software 8.7.1

cisco adaptive security appliance software 8.7.1.11

cisco adaptive security appliance software 8.7.1.3

cisco adaptive security appliance software 8.7.1.13

Vendor Advisories

A vulnerability in the Virtual Network Management Center (VNMC) policy code of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, local attacker to access the underlying Linux operating system with the privileges of the root user The vulnerability is due to insufficient sanitization of user supplied input An attacker ...