« Volver al listado

CVE-2014-0607

Estado: ModificadaAlta (10)—

Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and launching an executable file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-0607",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-07-24T14:55:06.410",
  "references": [
    {
      "url": "http://support.attachmate.com/techdocs/2700.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.attachmate.com/techdocs/2700.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and launching an executable file."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de subida de ficheros sin restricciones en Attachmate Verastream Process Designer (VPD) anterior a R6 SP1 Hotfix 1 permite a atacantes remotos ejecutar código arbitrario mediante la subida y el lanzamiento de un fichero ejecutable."
    }
  ],
  "lastModified": "2026-06-17T00:03:21.793",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:attachmate:verastream_process_designer:*:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63F1B842-82EB-42DD-B257-49F05CBE352D",
              "versionEndIncluding": "6.0"
            },
            {
              "criteria": "cpe:2.3:a:attachmate:verastream_process_designer:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "429816D9-8D69-4973-8803-AC39BFB4D40C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "<a href=\"http://cwe.mitre.org/data/definitions/434.html\" target=\"_blank\">CWE-434: Unrestricted Upload of File with Dangerous Type</a>",
  "sourceIdentifier": "cve@mitre.org"
}