PT-2014-7126 · Zenoss · Zenoss Core

Published

2014-12-15

·

Updated

2016-03-21

·

CVE-2014-6260

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zenoss Core versions through 5 Beta 3
Description The issue allows remote attackers to execute arbitrary commands or cause a denial of service by modifying the pager command string without requiring a password, potentially leveraging an unattended workstation.
Recommendations For Zenoss Core versions through 5 Beta 3, consider implementing password protection for modifying the pager command string to prevent unauthorized access. As a temporary workaround, ensure workstations are attended at all times to minimize the risk of exploitation.

Fix

DoS

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-6260

Affected Products

Zenoss Core