CVE-2014-2138

NONE
CVSS v3
4.3CVSS v2
0.21% EPSS (exploit probability)
CWE-20CWE

Description

CRLF injection vulnerability in the web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct redirection attacks via a crafted URL, aka Bug ID CSCun82349.

Affected routers (1)

VendorModelMatched viaAffected versionsFixed inPatch?
Ubiquiti Ubiquiti EdgeRouter 4 No

External references