CVE-2014-125121 - CVE House
Back to Database
Status published Critical CVE-2014-125121

Array Networks vAPV and vxAG Default Credential Privilege Escalation

Vulnerability Description

Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credentials (or SSH private key) and insecure permissions on a startup script. The devices ship with a default SSH login or a hardcoded DSA private key, allowing an attacker to authenticate remotely with limited privileges. Once authenticated, an attacker can overwrite the world-writable /ca/bin/monitor.sh script with arbitrary commands. Since this script is executed with elevated privileges through the backend binary, enabling the debug monitor via backend -c "debug monitor on" triggers execution of the attacker's payload as root. This allows full system compromise.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-125121

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • xistence

Affected Vendor

Array Networks

View all reports →

Affected Software

vAPV, vxAG
Vulnerable Versions:
8.3.2.17, 9.2.0.34

Timeline

Official Publish: July 31st, 2025
Last Modified: April 7th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)