« Volver al listado

CVE-2014-2959

Estado: ModificadaAlta (9)—

logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-2959",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 8.5,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-06-02T19:55:03.500",
  "references": [
    {
      "url": "http://secunia.com/advisories/59019",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/124908",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/67751",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/59019",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/124908",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/67751",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter."
    },
    {
      "lang": "es",
      "value": "logViewer.htm en el sistema de copias de seguridad de cintas Dell ML6000 con firmware anterior a i8.2.0.2 (641G.GS103) y el sistema de copias de seguridad de cintas Quantum Scalar i500 con firmware anterior a i8.2.2.1 (646G.GS002) permite a atacantes remotos ejecutar comandos arbitrarios a través de metacaracteres de shell en un parámetro de nombre de ruta."
    }
  ],
  "lastModified": "2026-06-17T00:07:24.210",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:powervault_ml6000_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4DFB91B9-A601-4F22-A1D2-D9DD5C8F9385",
              "versionEndIncluding": "i8.2.0.1_\\(641g.gs003\\)"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:powervault_ml6000:32u:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "136C9AB1-37AE-43EE-BAAC-39277789B734"
            },
            {
              "criteria": "cpe:2.3:h:dell:powervault_ml6000:41u:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33A96FD1-2005-41BE-ACE5-33AC136F7206"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:quantum:scalar_i500_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E26485A-B28F-42DF-8650-59A7D7C9D554",
              "versionEndIncluding": "i8.2.2.1_\\(646g.gs002\\)"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:quantum:scalar_i500:5u:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6AA8B64-A78C-4B51-B29B-21CF2AEF9484"
            },
            {
              "criteria": "cpe:2.3:h:quantum:scalar_i500:14u:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6FFB7DA-15EB-4053-9440-A30F8E434F5C"
            },
            {
              "criteria": "cpe:2.3:h:quantum:scalar_i500:23u:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C39DFB77-7945-4CA0-9B66-AF3908FE515D"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}