CVE-2014-6261: Code Injection
Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1) spoofing the callhome server or (2) deploying a crafted web site that is visited during a login session, aka ZEN-12657.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6261?
CVE-2014-6261 is classified as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2014-6261?
To mitigate CVE-2014-6261, it is recommended to upgrade Zenoss Core to a version that has addressed this vulnerability.
What systems are affected by CVE-2014-6261?
CVE-2014-6261 affects multiple versions of Zenoss Core, including versions up to 5 Beta 3 and several versions down to 2.4.0.
Can CVE-2014-6261 be exploited remotely?
Yes, CVE-2014-6261 can be exploited remotely by attackers through spoofing the callhome server or using a crafted web page.
What is the updated status of Zenoss regarding CVE-2014-6261?
Zenoss has released updates in later versions that patch the vulnerabilities associated with CVE-2014-6261.