ID

VAR-201410-0924


CVE

CVE-2014-6433


TITLE

GoPro HERO 3+ of gpExec Vulnerable to arbitrary file execution

Trust: 0.8

sources: JVNDB: JVNDB-2014-004601

DESCRIPTION

gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action. Authentication is not required to exploit this vulnerability.The specific flaw exists within the gpExec component. This component performs insufficient parameter validation on the a1/a2 parameters when the c1/c2 parameters are set to "start". Successful exploitation will allow an attacker to execute an arbitrary file on the target device. The GoPro HERO 3+ is a sports camera. Failed exploit attempts will likely result in denial-of-service conditions

Trust: 3.15

sources: NVD: CVE-2014-6433 // JVNDB: JVNDB-2014-004601 // ZDI: ZDI-14-347 // CNVD: CNVD-2014-06579 // BID: 70246 // VULHUB: VHN-74377

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-06579

AFFECTED PRODUCTS

vendor:gopromodel:heroscope:eqversion:3\+

Trust: 2.6

vendor:gopromodel:heroscope:eqversion:3+

Trust: 2.2

vendor:gopromodel:hero 3+scope: - version: -

Trust: 0.7

vendor:gopromodel:heroscope:eqversion:3+0

Trust: 0.3

sources: ZDI: ZDI-14-347 // CNVD: CNVD-2014-06579 // BID: 70246 // JVNDB: JVNDB-2014-004601 // CNNVD: CNNVD-201410-138 // NVD: CVE-2014-6433

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-6433
value: HIGH

Trust: 1.0

NVD: CVE-2014-6433
value: HIGH

Trust: 0.8

ZDI: CVE-2014-6433
value: HIGH

Trust: 0.7

CNVD: CNVD-2014-06579
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201410-138
value: CRITICAL

Trust: 0.6

VULHUB: VHN-74377
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-6433
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 2.5

CNVD: CNVD-2014-06579
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-74377
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: ZDI: ZDI-14-347 // CNVD: CNVD-2014-06579 // VULHUB: VHN-74377 // JVNDB: JVNDB-2014-004601 // CNNVD: CNNVD-201410-138 // NVD: CVE-2014-6433

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.9

sources: VULHUB: VHN-74377 // JVNDB: JVNDB-2014-004601 // NVD: CVE-2014-6433

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201410-138

TYPE

code injection

Trust: 0.6

sources: CNNVD: CNNVD-201410-138

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-004601

PATCH

title:Top Pageurl:http://jp.gopro.com/

Trust: 0.8

sources: JVNDB: JVNDB-2014-004601

EXTERNAL IDS

db:NVDid:CVE-2014-6433

Trust: 4.1

db:ZDIid:ZDI-14-347

Trust: 4.1

db:BIDid:70246

Trust: 1.0

db:JVNDBid:JVNDB-2014-004601

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-2162

Trust: 0.7

db:CNVDid:CNVD-2014-06579

Trust: 0.6

db:CNNVDid:CNNVD-201410-138

Trust: 0.6

db:VULHUBid:VHN-74377

Trust: 0.1

sources: ZDI: ZDI-14-347 // CNVD: CNVD-2014-06579 // VULHUB: VHN-74377 // BID: 70246 // JVNDB: JVNDB-2014-004601 // CNNVD: CNNVD-201410-138 // NVD: CVE-2014-6433

REFERENCES

url:http://www.zerodayinitiative.com/advisories/zdi-14-347/

Trust: 3.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-6433

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-6433

Trust: 0.8

url:http://shop.gopro.com/cameras

Trust: 0.3

sources: CNVD: CNVD-2014-06579 // VULHUB: VHN-74377 // BID: 70246 // JVNDB: JVNDB-2014-004601 // CNNVD: CNNVD-201410-138 // NVD: CVE-2014-6433

CREDITS

Anonymous

Trust: 1.0

sources: ZDI: ZDI-14-347 // BID: 70246

SOURCES

db:ZDIid:ZDI-14-347
db:CNVDid:CNVD-2014-06579
db:VULHUBid:VHN-74377
db:BIDid:70246
db:JVNDBid:JVNDB-2014-004601
db:CNNVDid:CNNVD-201410-138
db:NVDid:CVE-2014-6433

LAST UPDATE DATE

2025-04-13T23:35:14.106000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-14-347date:2014-10-02T00:00:00
db:CNVDid:CNVD-2014-06579date:2014-10-10T00:00:00
db:VULHUBid:VHN-74377date:2014-10-08T00:00:00
db:BIDid:70246date:2014-10-02T00:00:00
db:JVNDBid:JVNDB-2014-004601date:2014-10-09T00:00:00
db:CNNVDid:CNNVD-201410-138date:2014-10-14T00:00:00
db:NVDid:CVE-2014-6433date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:ZDIid:ZDI-14-347date:2014-10-02T00:00:00
db:CNVDid:CNVD-2014-06579date:2014-10-10T00:00:00
db:VULHUBid:VHN-74377date:2014-10-07T00:00:00
db:BIDid:70246date:2014-10-02T00:00:00
db:JVNDBid:JVNDB-2014-004601date:2014-10-09T00:00:00
db:CNNVDid:CNNVD-201410-138date:2014-10-14T00:00:00
db:NVDid:CVE-2014-6433date:2014-10-07T14:55:06.860