Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-3440

Overview

Vulnerability Score 9.0 9.0
CVE Id CVE-2014-3440
Last Modified 22 Jan 2015 08:47:49
Published 21 Jan 2015 10:17:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2014-3440

Summary

The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary commands by leveraging client-system access to upload a log file.

Vulnerable Systems

Application

  • Symantec Critical System Protection 5.2.9

  • Symantec Data Center Security 6.0.0


References

CONFIRM - http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20150119_00

BID - 72091


Last Updated: 27 May 2016 11:07:35