No analysis available yet.
Vendor Solution
All users of affected Innominate mGuard devices may either update to one of the following firmware versions: 7.6.4, 8.0.3, 8.1.0, 8.1.1, or higher, or use the hotfix-CVE-2014-2356.tar.gz patch-update to fix their systems without updating any other component. The patch can be applied by either uploading the patch-update as “Local Update” or by the “Online Update” functionality and using hotfix-CVE-2014-2356 as “Package set name.” In addition, Innominate recommends limiting access to the administrative interfaces via firewall rules to the minimum necessary.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-2393 | Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request. |
Fri, 03 Oct 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Innominate mGuard Exposure of Sensitive Information to an Unauthorized Actor | |
| References |
| |
| Metrics |
cvssV2_0
|
cvssV2_0
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-10-03T17:08:22.828Z
Reserved: 2014-03-13T00:00:00.000Z
Link: CVE-2014-2356
No data.
Status : Deferred
Published: 2014-07-30T14:55:06.680
Modified: 2025-10-03T18:15:32.813
Link: CVE-2014-2356
No data.
OpenCVE Enrichment
No data.
EUVD