CVE-2014-5502
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
07/10/2014
Last modified:
12/04/2025
Description
The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) ccc_flush_sql_file opcode.
Impact
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:cyberoam:cyberoam_os:*:ga:*:*:*:*:*:* | 10.4 (including) | |
| cpe:2.3:o:cyberoam:cyberoam_os:*:rc4:*:*:*:*:*:* | 10.6.1 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://kb.cyberoam.com/default.asp?id=3049
- http://www.zerodayinitiative.com/advisories/ZDI-14-328/
- http://www.zerodayinitiative.com/advisories/ZDI-14-331/
- http://www.zerodayinitiative.com/advisories/ZDI-14-332/
- http://www.zerodayinitiative.com/advisories/ZDI-14-333/
- http://kb.cyberoam.com/default.asp?id=3049
- http://www.zerodayinitiative.com/advisories/ZDI-14-328/
- http://www.zerodayinitiative.com/advisories/ZDI-14-331/
- http://www.zerodayinitiative.com/advisories/ZDI-14-332/
- http://www.zerodayinitiative.com/advisories/ZDI-14-333/



