4.6
CVE-2014-7180
- EPSS 0.46%
- Veröffentlicht 25.10.2014 00:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by modifying these files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Electric Cloud ≫ Electriccommander Version <= 4.2.5
Electric Cloud ≫ Electriccommander Version5.0.0
Electric Cloud ≫ Electriccommander Version5.0.1
Electric Cloud ≫ Electriccommander Version5.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.46% | 0.361 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
http://docs.electric-cloud.com/commander_doc/5_0_3/HTML5/ReleaseNotes/commander_releasenotes.htm
http://packetstormsecurity.com/files/128819/ElectricCommander-4.2.4.71224-Privilege-Escalation.html
http://seclists.org/fulldisclosure/2014/Oct/104
http://www.secureworks.com/advisories/SWRX-2014-010/SWRX-2014-010.pdf
http://www.secureworks.com/cyber-threat-intelligence/advisories/SWRX-2014-010/
http://www.securityfocus.com/bid/70722
https://exchange.xforce.ibmcloud.com/vulnerabilities/97735