ID

VAR-201410-0925


CVE

CVE-2014-6434


TITLE

GoPro HERO 3+ of gpExec Vulnerable to arbitrary command execution

Trust: 0.8

sources: JVNDB: JVNDB-2014-004602

DESCRIPTION

gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action. Authentication is not required to exploit this vulnerability.The specific flaw exists within the gpExec component. This component performs insufficient parameter validation on the a1/a2 parameters when the c1/c2 parameters are set to "restart". Successful exploitation will allow an attacker to execute arbitrary commands on the target device. The GoPro HERO 3+ is a sports camera. Failed exploit attempts will likely result in denial-of-service conditions

Trust: 3.15

sources: NVD: CVE-2014-6434 // JVNDB: JVNDB-2014-004602 // ZDI: ZDI-14-348 // CNVD: CNVD-2014-06580 // BID: 70250 // VULHUB: VHN-74378

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-06580

AFFECTED PRODUCTS

vendor:gopromodel:heroscope:eqversion:3\+

Trust: 2.6

vendor:gopromodel:heroscope:eqversion:3+

Trust: 2.2

vendor:gopromodel:hero 3+scope: - version: -

Trust: 0.7

vendor:gopromodel:heroscope:eqversion:3+0

Trust: 0.3

sources: ZDI: ZDI-14-348 // CNVD: CNVD-2014-06580 // BID: 70250 // JVNDB: JVNDB-2014-004602 // CNNVD: CNNVD-201410-139 // NVD: CVE-2014-6434

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-6434
value: HIGH

Trust: 1.0

NVD: CVE-2014-6434
value: HIGH

Trust: 0.8

ZDI: CVE-2014-6434
value: HIGH

Trust: 0.7

CNVD: CNVD-2014-06580
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201410-139
value: CRITICAL

Trust: 0.6

VULHUB: VHN-74378
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-6434
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 2.5

CNVD: CNVD-2014-06580
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-74378
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: ZDI: ZDI-14-348 // CNVD: CNVD-2014-06580 // VULHUB: VHN-74378 // JVNDB: JVNDB-2014-004602 // CNNVD: CNNVD-201410-139 // NVD: CVE-2014-6434

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.9

sources: VULHUB: VHN-74378 // JVNDB: JVNDB-2014-004602 // NVD: CVE-2014-6434

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201410-139

TYPE

operating system commend injection

Trust: 0.6

sources: CNNVD: CNNVD-201410-139

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-004602

PATCH

title:Top Pageurl:http://jp.gopro.com/

Trust: 0.8

sources: JVNDB: JVNDB-2014-004602

EXTERNAL IDS

db:NVDid:CVE-2014-6434

Trust: 4.1

db:ZDIid:ZDI-14-348

Trust: 4.1

db:BIDid:70250

Trust: 1.0

db:JVNDBid:JVNDB-2014-004602

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-2168

Trust: 0.7

db:CNVDid:CNVD-2014-06580

Trust: 0.6

db:CNNVDid:CNNVD-201410-139

Trust: 0.6

db:VULHUBid:VHN-74378

Trust: 0.1

sources: ZDI: ZDI-14-348 // CNVD: CNVD-2014-06580 // VULHUB: VHN-74378 // BID: 70250 // JVNDB: JVNDB-2014-004602 // CNNVD: CNNVD-201410-139 // NVD: CVE-2014-6434

REFERENCES

url:http://www.zerodayinitiative.com/advisories/zdi-14-348/

Trust: 3.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-6434

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-6434

Trust: 0.8

url:http://shop.gopro.com/cameras

Trust: 0.3

sources: CNVD: CNVD-2014-06580 // VULHUB: VHN-74378 // BID: 70250 // JVNDB: JVNDB-2014-004602 // CNNVD: CNNVD-201410-139 // NVD: CVE-2014-6434

CREDITS

Brian Gorenc - HP Zero Day Initiative

Trust: 1.0

sources: ZDI: ZDI-14-348 // BID: 70250

SOURCES

db:ZDIid:ZDI-14-348
db:CNVDid:CNVD-2014-06580
db:VULHUBid:VHN-74378
db:BIDid:70250
db:JVNDBid:JVNDB-2014-004602
db:CNNVDid:CNNVD-201410-139
db:NVDid:CVE-2014-6434

LAST UPDATE DATE

2025-04-13T23:42:06.373000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-14-348date:2014-10-02T00:00:00
db:CNVDid:CNVD-2014-06580date:2014-10-10T00:00:00
db:VULHUBid:VHN-74378date:2014-10-08T00:00:00
db:BIDid:70250date:2014-10-02T00:00:00
db:JVNDBid:JVNDB-2014-004602date:2014-10-09T00:00:00
db:CNNVDid:CNNVD-201410-139date:2014-10-16T00:00:00
db:NVDid:CVE-2014-6434date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:ZDIid:ZDI-14-348date:2014-10-02T00:00:00
db:CNVDid:CNVD-2014-06580date:2014-10-10T00:00:00
db:VULHUBid:VHN-74378date:2014-10-07T00:00:00
db:BIDid:70250date:2014-10-02T00:00:00
db:JVNDBid:JVNDB-2014-004602date:2014-10-09T00:00:00
db:CNNVDid:CNNVD-201410-139date:2014-10-14T00:00:00
db:NVDid:CVE-2014-6434date:2014-10-07T14:55:06.907