« Volver al listado

CVE-2014-3419

Estado: ModificadaAlta (7.2)—

Infoblox NetMRI before 6.8.5 has a default password of admin for the "root" MySQL database account, which makes it easier for local users to obtain access via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-3419",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-07-15T14:55:09.683",
  "references": [
    {
      "url": "http://blog.depthsecurity.com/2014/07/os-command-injection-in-infoblox-netmri.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/127410/Infoblox-6.8.4.x-Weak-MySQL-Password.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/532710/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/68473",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1030542",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/94450",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/depthsecurity/NetMRI-2014-3418",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://blog.depthsecurity.com/2014/07/os-command-injection-in-infoblox-netmri.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.com/files/127410/Infoblox-6.8.4.x-Weak-MySQL-Password.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/532710/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/68473",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1030542",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/94450",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/depthsecurity/NetMRI-2014-3418",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Infoblox NetMRI before 6.8.5 has a default password of admin for the \"root\" MySQL database account, which makes it easier for local users to obtain access via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Infoblox NetMRI anterior a 6.8.5 tiene una contraseña de administración por defecto para la cuenta de la base de datos MySQL 'root', lo que facilita a usuarios locales obtener el acceso a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:08:09.107",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:infoblox:netmri:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7C8505F-1ECA-41DC-A7A7-2357EAD6F2AE",
              "versionEndIncluding": "6.8.4"
            },
            {
              "criteria": "cpe:2.3:a:infoblox:netmri:6.0.2.42:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BE2F6EF-EDC9-46BF-BAE9-3DF54D6D81C0"
            },
            {
              "criteria": "cpe:2.3:a:infoblox:netmri:6.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA557660-0B78-4D48-A264-B6B391FA1755"
            },
            {
              "criteria": "cpe:2.3:a:infoblox:netmri:6.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A8A7042-1A18-4F56-8449-26E0F17864B8"
            },
            {
              "criteria": "cpe:2.3:a:infoblox:netmri:6.2.1.48:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EE9F395-4A62-47EF-9265-99FCA07FA479"
            },
            {
              "criteria": "cpe:2.3:a:infoblox:netmri:6.8.2.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8FF51070-50CA-423B-9FA9-146991A9BDE5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}