Vulnerability CVE-2014-7989


Published: 2014-11-07

Description:
Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 command, aka Bug ID CSCuq38176.

CVSS2 => (AV:L/AC:L/Au:S/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
10/10
3.1/10
Exploit range
Attack complexity
Authentication
Local
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Cisco -> B200 m3 
Cisco -> B200 m4 
Cisco -> B22 m3 
Cisco -> B230 m2 
Cisco -> B260 m4 
Cisco -> B420 m3 
Cisco -> B440 m2 
Cisco -> B460 m4 

 References:
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7989
http://www.securityfocus.com/bid/70969
http://www.securitytracker.com/id/1031178
https://exchange.xforce.ibmcloud.com/vulnerabilities/98530

Copyright 2024, cxsecurity.com

 

Back to Top