CVE-2014-3418: OS Command Injection
Published Jul 15, 2014
·Updated
config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipjackUsername parameter.
Affected Software
6 affected components
Infoblox NETMRI<=6.8.4
Infoblox NETMRI=6.0.2.42
Infoblox NETMRI=6.1.2
Infoblox NETMRI=6.2.1
Infoblox NETMRI=6.2.1.48
Infoblox NETMRI=6.8.2.11
Event History
Jul 15, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3418?
CVE-2014-3418 is classified as a high-severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2014-3418?
To fix CVE-2014-3418, upgrade Infoblox NetMRI to version 6.8.5 or later.
3
What types of attacks are possible with CVE-2014-3418?
CVE-2014-3418 allows remote attackers to execute arbitrary commands on the affected system.
4
Which versions of Infoblox NetMRI are affected by CVE-2014-3418?
CVE-2014-3418 affects Infoblox NetMRI versions prior to 6.8.5 and specific earlier versions like 6.0.2.42, 6.1.2, 6.2.1, and 6.8.2.11.
5
What is the impact of exploiting CVE-2014-3418?
Exploitation of CVE-2014-3418 can lead to unauthorized access and control over the impacted Infoblox NetMRI system.