CVE-2014-2565: OS Command Injection
Published Apr 30, 2014
·Updated
The commandline interface in Blue Coat Content Analysis System (CAS) 1.1 before 1.1.4.2 allows remote administrators to execute arbitrary commands via unspecified vectors, related to "command injection."
Affected Software
8 affected components
bluecoat Content Analysis System Software<=1.1.2.1
bluecoat Content Analysis System Software=1.1
bluecoat Content Analysis System Software=1.1.1.1
bluecoat Content Analysis System
All of the following
Any of the following
bluecoat Content Analysis System Software<=1.1.2.1
bluecoat Content Analysis System Software=1.1
bluecoat Content Analysis System Software=1.1.1.1
bluecoat Content Analysis System
Event History
Apr 30, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:22 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2565?
CVE-2014-2565 has a CVSS score indicating it is a high severity vulnerability due to command injection risks.
2
How do I fix CVE-2014-2565?
To fix CVE-2014-2565, upgrade the Blue Coat Content Analysis System to version 1.1.4.2 or later.
3
What versions are affected by CVE-2014-2565?
CVE-2014-2565 affects Blue Coat Content Analysis System versions prior to 1.1.4.2.
4
What type of vulnerability is CVE-2014-2565?
CVE-2014-2565 is categorized as a command injection vulnerability.
5
Who can exploit CVE-2014-2565?
Remote administrators can exploit CVE-2014-2565 to execute arbitrary commands on the affected system.