CVE-2014-6260: Command Injection
Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary commands or cause a denial of service (paging outage) by leveraging an unattended workstation, aka ZEN-15412.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6260?
CVE-2014-6260 has a severity rating of high due to its potential for remote command execution.
How do I fix CVE-2014-6260?
To fix CVE-2014-6260, implement authentication controls to require a password for modifying the pager command string.
What software versions are affected by CVE-2014-6260?
CVE-2014-6260 affects Zenoss Core through version 5 Beta 3, including multiple versions down to 2.4.0.
Can CVE-2014-6260 lead to denial of service?
Yes, CVE-2014-6260 can cause a denial of service through paging outages if exploited by an attacker.
Is CVE-2014-6260 remotely exploitable?
Yes, CVE-2014-6260 can be exploited remotely, allowing attackers to execute arbitrary commands.