CVE-2014-7288: Critical severity symantec encryption management server vulnerability
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7288?
CVE-2014-7288 has a critical severity level due to its potential for remote code execution by authenticated administrators.
How do I fix CVE-2014-7288?
To fix CVE-2014-7288, upgrade to Symantec Encryption Management Server or PGP Universal Server version 3.3.2 MP7 or later.
What versions are affected by CVE-2014-7288?
CVE-2014-7288 affects versions prior to 3.3.2 MP7 of Symantec Encryption Management Server and PGP Universal Server.
Who can exploit CVE-2014-7288?
CVE-2014-7288 can be exploited by remote authenticated administrators with access to the system.
What type of vulnerability is CVE-2014-7288?
CVE-2014-7288 is classified as a remote command execution vulnerability.