CVE-2014-2119 describes a critical vulnerability in Cisco AsyncOS Software for Email Security Appliance (ESA) and Content Security Management Appliance (SMA) that allows remote authenticated users to execute arbitrary code with root privileges. The vulnerability, identified as a weakness in the End User Safelist/Blocklist (SLBL) service, can be exploited by uploading a modified SLBL database file via an FTP session. With a CVSS score of 8.5, it is considered highly severe due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.9.1-039CPE matchmatch criteria | cpe:2.3:o:cisco:ironport_asyncos:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:cisco:ironport_asyncos:8.0:*:*:*:*:*:*:* | ||
8.0.1CPE matchmatch criteria | cpe:2.3:o:cisco:ironport_asyncos:8.0.1:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:cisco:ironport_asyncos:8.1:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:cisco:content_security_management_appliance:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.