{ "schema_version": "1.4.0", "id": "GHSA-v7x3-c3f9-2xc9", "modified": "2022-05-17T04:19:17Z", "published": "2022-05-17T04:19:17Z", "aliases": [ "CVE-2014-7994" ], "details": "Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to an unspecified HTTP handler on the local network, aka Cisco-Meraki defect ID 00301991.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-7994" }, { "type": "WEB", "url": "https://dashboard.meraki.com/firmware_security" }, { "type": "WEB", "url": "http://tools.cisco.com/security/center/viewAlert.x?alertId=36798" } ], "database_specific": { "cwe_ids": [ "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2014-12-24T00:59:00Z" } }