Lucene search

K
cveMitreCVE-2014-2541
HistoryApr 08, 2014 - 11:47 p.m.

CVE-2014-2541

2014-04-0823:47:28
CWE-264
mitre
web.nvd.nist.gov
30
tibco rendezvous
messaging appliance
substation es
access control
vulnerability
cve-2014-2541
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

69.1%

The Rendezvous Daemon (rvd), Rendezvous Routing Daemon (rvrd), Rendezvous Secure Daemon (rvsd), and Rendezvous Secure Routing Daemon (rvsrd) in TIBCO Rendezvous before 8.4.2, Messaging Appliance before 8.7.1, and Substation ES before 2.8.1 do not properly implement access control, which allows remote attackers to obtain sensitive information or modify transmitted information via unspecified vectors.

Affected configurations

Nvd
Node
tibcorendezvousRange≀8.4.1
OR
tibcorendezvousMatch7.4.11
OR
tibcorendezvousMatch7.5.1
OR
tibcorendezvousMatch7.5.2
OR
tibcorendezvousMatch7.5.3
OR
tibcorendezvousMatch7.5.4
OR
tibcorendezvousMatch8.2.1
OR
tibcorendezvousMatch8.3.0
OR
tibcorendezvousMatch8.3.1
OR
tibcorendezvousMatch8.10
OR
tibcosubstantiation_esRange≀2.8.0
OR
tibcomessaging_applianceRange≀8.7.0
VendorProductVersionCPE
tibcorendezvous*cpe:2.3:a:tibco:rendezvous:*:*:*:*:*:*:*:*
tibcorendezvous7.4.11cpe:2.3:a:tibco:rendezvous:7.4.11:*:*:*:*:*:*:*
tibcorendezvous7.5.1cpe:2.3:a:tibco:rendezvous:7.5.1:*:*:*:*:*:*:*
tibcorendezvous7.5.2cpe:2.3:a:tibco:rendezvous:7.5.2:*:*:*:*:*:*:*
tibcorendezvous7.5.3cpe:2.3:a:tibco:rendezvous:7.5.3:*:*:*:*:*:*:*
tibcorendezvous7.5.4cpe:2.3:a:tibco:rendezvous:7.5.4:*:*:*:*:*:*:*
tibcorendezvous8.2.1cpe:2.3:a:tibco:rendezvous:8.2.1:*:*:*:*:*:*:*
tibcorendezvous8.3.0cpe:2.3:a:tibco:rendezvous:8.3.0:*:*:*:*:*:*:*
tibcorendezvous8.3.1cpe:2.3:a:tibco:rendezvous:8.3.1:*:*:*:*:*:*:*
tibcorendezvous8.10cpe:2.3:a:tibco:rendezvous:8.10:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

69.1%

Related for CVE-2014-2541