Vulnerability CVE-2014-2959


Published: 2014-06-02

Description:
logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter.

Type:

CWE-78

(Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') )

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9/10
8.5/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Partial
Partial
Affected software
Quantum -> Scalar i500 
Quantum -> Scalar i500 firmware 
DELL -> Powervault ml6000 
DELL -> Powervault ml6000 firmware 

 References:
http://www.kb.cert.org/vuls/id/124908
http://www.securityfocus.com/bid/67751
http://secunia.com/advisories/59019

Copyright 2024, cxsecurity.com

 

Back to Top