6.8

CVE-2014-7989

Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 command, aka Bug ID CSCuq38176.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ B200 M3 Version -
Cisco ≫ B200 M4 Version -
Cisco ≫ B22 M3 Version -
Cisco ≫ B230 M2 Version -
Cisco ≫ B260 M4 Version -
Cisco ≫ B420 M3 Version -
Cisco ≫ B440 M2 Version -
Cisco ≫ B460 M4 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.263
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 3.1 10
AV:L/AC:L/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7989
Vendor Advisory
http://www.securityfocus.com/bid/70969
http://www.securitytracker.com/id/1031178
https://exchange.xforce.ibmcloud.com/vulnerabilities/98530