5

CVE-2014-9248

Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain access via a brute-force attack, aka ZEN-15406.

Data is provided by the National Vulnerability Database (NVD)
ZenossZenoss Core Updatebeta_3 Version <= 5.0.0
ZenossZenoss Core Version2.4.0
ZenossZenoss Core Version2.4.5
ZenossZenoss Core Version2.5.0
ZenossZenoss Core Version2.5.1
ZenossZenoss Core Version2.5.2
ZenossZenoss Core Version3.0.0
ZenossZenoss Core Version3.0.1
ZenossZenoss Core Version3.0.2
ZenossZenoss Core Version3.0.3
ZenossZenoss Core Version3.1.0
ZenossZenoss Core Version3.2.0
ZenossZenoss Core Version3.2.1
ZenossZenoss Core Version4.2.0
ZenossZenoss Core Version4.2.3
ZenossZenoss Core Version4.2.4
ZenossZenoss Core Version4.2.5
ZenossZenoss Core Version5.0.0
ZenossZenoss Core Version5.0.0 Updatebeta_1
ZenossZenoss Core Version5.0.0 Updatebeta_2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.53% 0.662
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N