Lucene search

K
cveJpcertCVE-2014-7266
HistoryFeb 01, 2015 - 3:59 p.m.

CVE-2014-7266

2015-02-0115:59:00
CWE-399
jpcert
web.nvd.nist.gov
24
cybozu
remote service manager
vulnerability
denial of service
cve-2014-7266
nvd

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.8

Confidence

Low

EPSS

0.006

Percentile

79.2%

Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial of service (CPU consumption) via vectors that trigger colliding hash-table keys. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1983.

Affected configurations

Nvd
Node
cybozuremote_service_managerMatch2.3.0
OR
cybozuremote_service_managerMatch3.1.0
OR
cybozuremote_service_managerMatch3.1.1
OR
cybozuremote_service_managerMatch3.1.2
VendorProductVersionCPE
cybozuremote_service_manager2.3.0cpe:2.3:a:cybozu:remote_service_manager:2.3.0:*:*:*:*:*:*:*
cybozuremote_service_manager3.1.0cpe:2.3:a:cybozu:remote_service_manager:3.1.0:*:*:*:*:*:*:*
cybozuremote_service_manager3.1.1cpe:2.3:a:cybozu:remote_service_manager:3.1.1:*:*:*:*:*:*:*
cybozuremote_service_manager3.1.2cpe:2.3:a:cybozu:remote_service_manager:3.1.2:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.8

Confidence

Low

EPSS

0.006

Percentile

79.2%

Related for CVE-2014-7266