Vulnerability Description
Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 command, aka Bug ID CSCuq38176.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | B200 M3 | - |
| Cisco | B200 M4 | - |
| Cisco | B22 M3 | - |
| Cisco | B230 M2 | - |
| Cisco | B260 M4 | - |
| Cisco | B420 M3 | - |
| Cisco | B440 M2 | - |
| Cisco | B460 M4 | - |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7989Vendor Advisory
- http://www.securityfocus.com/bid/70969
- http://www.securitytracker.com/id/1031178
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98530
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-7989Vendor Advisory
- http://www.securityfocus.com/bid/70969
- http://www.securitytracker.com/id/1031178
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98530
FAQ
What is CVE-2014-7989?
CVE-2014-7989 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 command, aka Bug ID CSCuq38176.
How severe is CVE-2014-7989?
CVE-2014-7989 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-7989?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco B200 M3, Cisco B200 M4, Cisco B22 M3, Cisco B230 M2, Cisco B260 M4.