Lucene search

K
cve[email protected]CVE-2015-2746
HistoryMar 26, 2015 - 2:59 p.m.

CVE-2015-2746

2015-03-2614:59:03
CWE-77
web.nvd.nist.gov
28
cve-2015-2746
network diagnostics tool
appliance manager
command line utility
security vulnerability

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.054 Low

EPSS

Percentile

93.2%

The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the “second” parameter of a command, as demonstrated by the Destination parameter in the ping command.

Affected configurations

NVD
Node
websensetritonMatch7.8.3
OR
websensev-series_appliancesRange7.7

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.054 Low

EPSS

Percentile

93.2%

Related for CVE-2015-2746