CVE-2014-125001

A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions is possible. Firewalling or disabling the service is recommended.
References
Link Resource
http://www.remote-exploit.org/archives/2014/06/03/ride_with_the_devil/ Exploit Third Party Advisory
https://vuldb.com/?id.13428 Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:cardosystems:scala_rider_q3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cardosystems:scala_rider_q3:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-05-24 16:15

Updated : 2024-02-28 19:09


NVD link : CVE-2014-125001

Mitre link : CVE-2014-125001

CVE.ORG link : CVE-2014-125001


JSON object : View

Products Affected

cardosystems

  • scala_rider_q3_firmware
  • scala_rider_q3
CWE
CWE-269

Improper Privilege Management