CVE-2014-5502

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
07/10/2014
Last modified:
12/04/2025

Description

The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) ccc_flush_sql_file opcode.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cyberoam:cyberoam_os:*:ga:*:*:*:*:*:* 10.4 (including)
cpe:2.3:o:cyberoam:cyberoam_os:*:rc4:*:*:*:*:*:* 10.6.1 (including)