First published: Mon Apr 28 2014(Updated: )
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to recoveryconsole/bpl/snmpd.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Unitrends Enterprise Backup | =7.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3008 is considered a critical vulnerability due to its ability to allow remote authenticated users to execute arbitrary commands.
To fix CVE-2014-3008, upgrade to a later version of Unitrends Enterprise Backup that addresses this vulnerability.
CVE-2014-3008 specifically affects Unitrends Enterprise Backup version 7.3.0.
Yes, CVE-2014-3008 can be exploited by remote authenticated users, allowing them to execute commands on the server.
Due to CVE-2014-3008, an attacker can execute any arbitrary commands through shell metacharacters.