MEDIUM · 6.8

CVE-2014-7989

Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 command, aka Bug ID CSCuq38176.

Vulnerability Description

Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 command, aka Bug ID CSCuq38176.

CVSS Score

6.8

MEDIUM

AV:L/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoB200 M3-
CiscoB200 M4-
CiscoB22 M3-
CiscoB230 M2-
CiscoB260 M4-
CiscoB420 M3-
CiscoB440 M2-
CiscoB460 M4-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-7989?

CVE-2014-7989 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 command, aka Bug ID CSCuq38176.

How severe is CVE-2014-7989?

CVE-2014-7989 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-7989?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco B200 M3, Cisco B200 M4, Cisco B22 M3, Cisco B230 M2, Cisco B260 M4.