Lucene search

K
ibmIBMFD1F32937109C80A806D164B1E91A508528F37B031340261625347A00A0BCCD0
HistoryJun 16, 2018 - 9:20 p.m.

Security Bulletin: IBM Security Network Protection is affected by Shell Command Injection vulnerability (CVE-2014-6183)

2018-06-1621:20:50
www.ibm.com
12

EPSS

0.002

Percentile

55.0%

Summary

A Shell Command Injection vulnerability has been discovered in IBM Security Network Protection.

Vulnerability Details

CVE-ID:CVE-2014-6183

**Description:**IBM Security Network Protection could allow a remote attacker to execute arbitrary commands on the system. An authenticated attacker could exploit this vulnerability to inject and execute arbitrary shell commands on the system.

CVSS:
CVSS Base Score: 9.0
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/98519 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C)

Affected Products and Versions

**Products:IBM Security Network Protection****(XGS)**models 3100, 4100, 5100, 7100

Firmware versions: 5.1, 5.1.1, 5.1.2, 5.1.2.1, 5.2, 5.3

Remediation/Fixes

IBM has provided patches for all affected versions. Follow the installation instructions in the README files included with the patch.

Workarounds and Mitigations

None

**

EPSS

0.002

Percentile

55.0%

Related for FD1F32937109C80A806D164B1E91A508528F37B031340261625347A00A0BCCD0