CVE-2014-3008: OS Command Injection
Published Apr 28, 2014
·Updated
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to recoveryconsole/bpl/snmpd.php.
Affected Software
1 affected component
Unitrends Enterprise Backup=7.3.0
Event History
Apr 28, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:09 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3008?
CVE-2014-3008 is considered a critical vulnerability due to its ability to allow remote authenticated users to execute arbitrary commands.
2
How do I fix CVE-2014-3008?
To fix CVE-2014-3008, upgrade to a later version of Unitrends Enterprise Backup that addresses this vulnerability.
3
What software is affected by CVE-2014-3008?
CVE-2014-3008 specifically affects Unitrends Enterprise Backup version 7.3.0.
4
Can CVE-2014-3008 be exploited remotely?
Yes, CVE-2014-3008 can be exploited by remote authenticated users, allowing them to execute commands on the server.
5
What type of commands can be executed due to CVE-2014-3008?
Due to CVE-2014-3008, an attacker can execute any arbitrary commands through shell metacharacters.