6.8

CVE-2014-7989

Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 command, aka Bug ID CSCuq38176.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoB200 M3 Version-
CiscoB200 M4 Version-
CiscoB22 M3 Version-
CiscoB230 M2 Version-
CiscoB260 M4 Version-
CiscoB420 M3 Version-
CiscoB440 M2 Version-
CiscoB460 M4 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.218
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 3.1 10
AV:L/AC:L/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.