Lucene search

K
kasperskyKaspersky LabKLA10236
HistoryJul 03, 2014 - 12:00 a.m.

KLA10236 ACE vulnerability in Kerio Control

2014-07-0300:00:00
Kaspersky Lab
threats.kaspersky.com
20

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

41.7%

An SQL injection vulnerability was found in Kerio Control. By exploiting this vulnerability malicious users can execute arbitrary SQL. This vulnerability can be exploited remotely via a specially designed php call.

Original advisories

Release history

Exploitation

Public exploits exist for this vulnerability.

Related products

Kerio-Control

CVE list

CVE-2014-3857 high

Solution

Update to latest version

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • Kerio Control versions 8.3.1 and earlier

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

41.7%