PT-2014-4989 · Autodesk · Autodesk Vred Professional

Thomas Fischer

·

Publicado

2014-07-07

·

Atualizado

2014-07-07

·

CVE-2014-2967

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Autodesk VRED Professional 2014 versions before SR1 SP8
Description The issue allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server.
Recommendations For Autodesk VRED Professional 2014 versions before SR1 SP8, update to SR1 SP8 or later to resolve the issue.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-2967

Produtos afetados

Autodesk Vred Professional