6.5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.2 High
AI Score
Confidence
Low
0.001 Low
EPSS
Percentile
41.7%
An SQL injection vulnerability was found in Kerio Control. By exploiting this vulnerability malicious users can execute arbitrary SQL. This vulnerability can be exploited remotely via a specially designed php call.
Public exploits exist for this vulnerability.
CVE-2014-3857 high
Update to latest version
Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.