6.8

CVE-2014-7989

Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 command, aka Bug ID CSCuq38176.

Data is provided by the National Vulnerability Database (NVD)
CiscoB200 M3 Version-
CiscoB200 M4 Version-
CiscoB22 M3 Version-
CiscoB230 M2 Version-
CiscoB260 M4 Version-
CiscoB420 M3 Version-
CiscoB440 M2 Version-
CiscoB460 M4 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.218
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 3.1 10
AV:L/AC:L/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.