peter bassill · operator
$ cve CVE-2014-4865 JSON

CVE-2014-4865 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.2% (pctl 68)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attackers to hijack the authentication of arbitrary users.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.24% — more likely to be exploited than 68% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2014-09-10
Last modified2026-06-17

Affected (1)

VendorProduct
cacheguardcacheguardos

Public exploits

SourceTitleDate
exploit-dbCacheGuard-OS 5.7.7 - Cross-Site Request Forgery2014-09-15

References

→ the Explorer  ·  watch your stack  ·  NVD