« Volver al listado

CVE-2014-0633

Estado: ModificadaAlta (7.7)—

The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote attackers to execute arbitrary code by leveraging an unattended workstation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-0633",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.7,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:S/C:C/I:C/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 5.1,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-04-01T06:28:18.030",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2014-03/0157.html",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2014-03/0157.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote attackers to execute arbitrary code by leveraging an unattended workstation."
    },
    {
      "lang": "es",
      "value": "La interfaz gráfica de usuario en EMC VPLEX GeoSynchrony 4.x y 5.x anterior a 5.3 no valida debidamente valores de timeout de sesión, lo que podría facilitar a atacantes remotos ejecutar código arbitrario mediante el aprovechamiento de una estación de trabajo desatendida."
    }
  ],
  "lastModified": "2026-06-17T00:03:24.307",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:emc:vplex_geosynchrony:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C283DEAD-A5DB-4A74-84F6-749BFC265F2E"
            },
            {
              "criteria": "cpe:2.3:a:emc:vplex_geosynchrony:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D536831F-D76F-42CE-9351-3212027C8227"
            },
            {
              "criteria": "cpe:2.3:a:emc:vplex_geosynchrony:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BDBBB7B-19C8-404F-B22F-D3077EEF33F4"
            },
            {
              "criteria": "cpe:2.3:a:emc:vplex_geosynchrony:5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E6877D1-61BC-4A30-91AF-0948977B0C8D"
            },
            {
              "criteria": "cpe:2.3:a:emc:vplex_geosynchrony:5.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2A7C8A7-5F49-4B09-B6C1-9F2F2F0A314A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}