{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"mGuard","vendor":"Innominate","versions":[{"lessThanOrEqual":"8.1.3","status":"affected","version":"0","versionType":"custom"},{"status":"unaffected","version":"7.6.6"},{"status":"unaffected","version":"8.1.4"}]}],"credits":[{"lang":"en","type":"finder","value":"Innominate Security Technologies has identified a privilege escalation vulnerability affecting all mGuard devices."}],"datePublic":"2014-12-17T07:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting.</p>"}],"value":"Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting."}],"metrics":[{"cvssV2_0":{"accessComplexity":"MEDIUM","accessVector":"NETWORK","authentication":"SINGLE","availabilityImpact":"COMPLETE","baseScore":8.5,"confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","version":"2.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-269","description":"CWE-269","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert","dateUpdated":"2025-07-28T20:35:16.302Z"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.innominate.com/data/downloads/software/innominate_security_advisory_20141217_001_en.pdf"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-352-02"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Innominate has released firmware patches Version 7.6.6 and Version \n8.1.4 that mitigates the vulnerability in the mGuard firmware Version 7 \nand Version 8, respectively. Innominate recommends that customers using \nfirmware versions older than Version 7, which are no longer being \nmaintained, should upgrade to mGuard firmware Version 7.6.6 or Version \n8.1.4. Innominate also recommends that customers limit access to the \nadministrative interfaces to a minimum via firewall rules.</p>\n<p>For additional information on the vulnerability, Innominate’s security advisory is available on its web site at:</p><p><a target=\"_blank\" rel=\"nofollow\" href=\"http://www.innominate.com/en/downloads/security-advisories\">http://www.innominate.com/en/downloads/security-advisories</a></p>\n<p>Innominate’s firmware updates are available on its web site at:</p><p><a target=\"_blank\" rel=\"nofollow\" href=\"http://www.innominate.com/en/downloads/updates\">http://www.innominate.com/en/downloads/updates</a>&nbsp;&nbsp;<br></p>"}],"value":"Innominate has released firmware patches Version 7.6.6 and Version \n8.1.4 that mitigates the vulnerability in the mGuard firmware Version 7 \nand Version 8, respectively. Innominate recommends that customers using \nfirmware versions older than Version 7, which are no longer being \nmaintained, should upgrade to mGuard firmware Version 7.6.6 or Version \n8.1.4. Innominate also recommends that customers limit access to the \nadministrative interfaces to a minimum via firewall rules.\n\n\nFor additional information on the vulnerability, Innominate’s security advisory is available on its web site at:\n\n http://www.innominate.com/en/downloads/security-advisories \n\n\nInnominate’s firmware updates are available on its web site at:\n\n http://www.innominate.com/en/downloads/updates"}],"source":{"advisory":"ICSA-14-352-02","discovery":"INTERNAL"},"title":"Innominate mGuard Improper Privilege Management","x_generator":{"engine":"Vulnogram 0.2.0"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2014-9193","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.innominate.com/data/downloads/software/innominate_security_advisory_20141217_001_en.pdf","refsource":"CONFIRM","url":"http://www.innominate.com/data/downloads/software/innominate_security_advisory_20141217_001_en.pdf"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-14-352-02","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-14-352-02"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-06T13:40:24.558Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.innominate.com/data/downloads/software/innominate_security_advisory_20141217_001_en.pdf"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-14-352-02"}]}]},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2014-9193","datePublished":"2014-12-20T00:00:00.000Z","dateReserved":"2014-12-02T00:00:00.000Z","dateUpdated":"2025-07-28T20:35:16.302Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}