PT-2014-4989 · Autodesk · Autodesk Vred Professional

Thomas Fischer

·

Published

2014-07-07

·

Updated

2014-07-07

·

CVE-2014-2967

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Autodesk VRED Professional 2014 versions before SR1 SP8
Description The issue allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server.
Recommendations For Autodesk VRED Professional 2014 versions before SR1 SP8, update to SR1 SP8 or later to resolve the issue.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2967

Affected Products

Autodesk Vred Professional