7.9

CVE-2014-1649

The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLRPC request over HTTPS.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Workspace Streaming Version <= 7.5.0
Symantec ≫ Workspace Streaming Version 6.1
Symantec ≫ Workspace Streaming Version 6.1 Update sp1
Symantec ≫ Workspace Streaming Version 6.1 Update sp2
Symantec ≫ Workspace Streaming Version 6.1 Update sp3
Symantec ≫ Workspace Streaming Version 6.1 Update sp4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 42.31% 0.985
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.9 5.5 10
AV:A/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.exploit-db.com/exploits/33521
http://www.securityfocus.com/bid/67189
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20140512_00
Vendor Advisory
http://zerodayinitiative.com/advisories/ZDI-14-127/