Lucene search

K
cveMitreCVE-2014-2846
HistoryApr 28, 2014 - 2:09 p.m.

CVE-2014-2846

2014-04-2814:09:07
CWE-22
mitre
web.nvd.nist.gov
38
cve-2014-2846
information security
directory traversal
vulnerability
wd arkeia
firmware
remote attackers
php code execution

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.1

Percentile

95.0%

Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a …/./ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.

Affected configurations

Nvd
Node
westerndigitalarkeia_virtual_appliance_firmwareRange10.2.7
VendorProductVersionCPE
westerndigitalarkeia_virtual_appliance_firmware*cpe:2.3:o:westerndigital:arkeia_virtual_appliance_firmware:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.1

Percentile

95.0%