Vulnerability Description
Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Traffic Server | 2.0.0 |
References
- http://mail-archives.apache.org/mod_mbox/trafficserver-users/201407.mbox/%3CBFCE
- http://secunia.com/advisories/60375
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95495
- http://mail-archives.apache.org/mod_mbox/trafficserver-users/201407.mbox/%3CBFCE
- http://secunia.com/advisories/60375
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95495
FAQ
What is CVE-2014-3525?
CVE-2014-3525 is a vulnerability with a CVSS score of 10.0 (HIGH). Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.
How severe is CVE-2014-3525?
CVE-2014-3525 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3525?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Traffic Server.