Overview
Dell ML6000 and Quantum Scalar i500 tape backup system contain a command injection vulnerability.
Description
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Dell's and Quantum's advisories state the following: |
Impact
Dell's and Quantum's advisories state the following: |
Solution
Upgrade |
Restrict Access |
Vendor Information (Learn More)
Quantum Scalar i500 firmware versions i8.2.2 (645G.GS004) and below are affected. |
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
Dell Computer Corporation, Inc. | Affected | 14 Apr 2014 | 30 May 2014 |
Quantum | Affected | 14 Apr 2014 | 30 May 2014 |
If you are a vendor and your product is affected, let us know.
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | 9.0 | AV:N/AC:L/Au:N/C:C/I:P/A:P |
Temporal | 7.4 | E:F/RL:OF/RC:C |
Environmental | 6.3 | CDP:MH/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://www.dell.com/support/drivers/us/en/19/DriverDetails/Product/powervault-ml6000?driverId=XCC7W&osCode=WNET&fileId=3369748178&languageCode=en&categoryId=TA
- http://www.quantum.com/serviceandsupport/softwareanddocumentationdownloads/si500/index.aspx
Credit
Thanks to Benjamin Buchanan for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
- CVE IDs: CVE-2014-2959
- Date Public: 15 5월 2014
- Date First Published: 30 5월 2014
- Date Last Updated: 30 5월 2014
- Document Revision: 21
'취약점 정보1' 카테고리의 다른 글
2014-06-02 취약점정리 (0) | 2014.06.03 |
---|---|
Technical Analysis Of The GnuTLS Hello Vulnerability (0) | 2014.06.02 |
Huawei E303 contains a cross-site request forgery vulnerability (0) | 2014.05.31 |
2014-05-31 취약점 정리 (0) | 2014.05.31 |
Alfresco Enterprise contains multiple cross-site scripting vulnerabilities (0) | 2014.05.28 |