| ID |
CVE-2014-2119
|
| Sažetak |
The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1-023 and Cisco Content Security Management Appliance (SMA) before 7.9.1-110 and 8.x before 8.1.1-013 allows remote authenticated users to execute arbitrary code with root privileges via an FTP session that uploads a modified SLBL database file, aka Bug IDs CSCug79377 and CSCug80118. |
| Reference |
|
| CVSS |
| Base: | 8.5 |
| Impact: | 10.0 |
| Exploitability: | 6.8 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| NETWORK |
MEDIUM |
SINGLE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| COMPLETE |
COMPLETE |
COMPLETE |
|
| CVSS vektor |
AV:N/AC:M/Au:S/C:C/I:C/A:C |
| Zadnje važnije ažuriranje |
30-10-2018 - 16:27 |
| Objavljeno |
21-03-2014 - 01:04 |