9.3
CVE-2014-1861
- EPSS 1.41%
- Veröffentlicht 18.02.2014 11:55:16
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which allows remote JCSB servers to execute arbitrary programs by providing a .EXE extension.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jetroplatforms ≫ Jetro Cockpit Secure Browsing Version4.3.1
Jetroplatforms ≫ Jetro Cockpit Secure Browsing Version4.3.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.41% | 0.692 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://archives.neohapsis.com/archives/bugtraq/2014-02/0075.html
http://blog.quaji.com/2014/02/remote-code-execution-on-all-enterprise.html