CVE-2014-0633: Input Validation
Published Mar 28, 2014
·Updated
The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote attackers to execute arbitrary code by leveraging an unattended workstation.
Affected Software
5 affected components
EMC VPLEX GeoSynchrony=4.0
EMC VPLEX GeoSynchrony=5.0
EMC VPLEX GeoSynchrony=5.1
EMC VPLEX GeoSynchrony=5.2
EMC VPLEX GeoSynchrony=5.2.1
Event History
Mar 28, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Apr 1, 2014
Data Sourced
via NVD·06:28 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0633?
CVE-2014-0633 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2014-0633?
To mitigate CVE-2014-0633, upgrade EMC VPLEX GeoSynchrony to version 5.3 or later.
3
What attack vector does CVE-2014-0633 utilize?
CVE-2014-0633 can be exploited by remote attackers leveraging unattended workstations.
4
Which versions of EMC VPLEX GeoSynchrony are affected by CVE-2014-0633?
CVE-2014-0633 affects EMC VPLEX GeoSynchrony versions 4.x and 5.x prior to 5.3.
5
What is the primary risk associated with CVE-2014-0633?
The primary risk of CVE-2014-0633 is the potential for attackers to execute arbitrary code on the affected system.