Silver Peak vx xss Vulnerability (CVE-2014-2974)
Release date:
Updated on:
Affected Systems:
Silver peak Silver Peak VX
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-2974
Silver Peak VX is a virtual WAN optimization solution.
Silver Peak VX version 6.2.2.0 _ 47968 has a Cross-Site Request Forgery Vulnerability in the implementation of/php/user_account.php, which allows unauthenticated attackers to create new administrator accounts.
<* Source: William Costa
Link: http://www.kb.cert.org/vuls/id/867980
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Silver peak
-----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.silver-peak.com/products-solutions/wan-optimization/vx-software
This article permanently updates the link address: