CVE-2014-8361

Vulnerability updated 2 months ago (2024-08-29T16:18:04.931Z)
Download STIX
Preview STIX
CVE-2014-8361 is a significant software vulnerability discovered in the design and implementation of Realtek SDK devices, Hadoop YARN servers, and Huawei HG532 routers. This flaw allows for command injection, enabling an attacker to execute arbitrary commands via SOAP, a protocol used for exchanging structured information in web services. Akamai's Security Intelligence and Response Team (SIRT) observed this vulnerability being exploited in several campaigns, alongside other unpatched zero-day vulnerabilities. The exploitation of CVE-2014-8361 was particularly noted in the distribution of malware such as HinataBot. Attackers took advantage of exposed Hadoop YARN servers and security flaws in Realtek SDK devices and Huawei HG532 routers to propagate their malicious activities. The vulnerability allowed attackers to manipulate the miniigd SOAP service on these devices, which played a crucial role in the infection process. Despite its high CVSS score of 8.8, indicating its severity, the CVE-2014-8361 vulnerability remained unpatched for a considerable period. This situation left many devices susceptible to attacks, highlighting the necessity for timely patch management and robust cybersecurity measures to mitigate such threats. It underscores the importance of staying abreast with the latest vulnerabilities and ensuring that all systems are regularly updated and patched to prevent potential exploits.
Description last updated: 2024-08-29T16:16:08.318Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Vulnerability
Hadoop
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Vulnerabilities
To see the evidence that has resulted in these vulnerability associations, create a free account
Alias DescriptionAssociation TypeVotes
The CVE-2017-17215 Vulnerability is associated with CVE-2014-8361. CVE-2017-17215 is a significant vulnerability found in Huawei HG532 routers, characterized as a flaw in software design or implementation. This vulnerability has been exploited to distribute malware through exposed Hadoop YARN servers and security flaws in Realtek SDK devices (CVE-2014-8361) and HuaUnspecified
2