CVE-2014-125001

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
24/05/2022
Last modified:
08/06/2022

Description

A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions is possible. Firewalling or disabling the service is recommended.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cardosystems:scala_rider_q3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cardosystems:scala_rider_q3:-:*:*:*:*:*:*:*