CVE-2014-9249: High severity zenoss vulnerability
The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open ports, aka ZEN-15408.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9249?
CVE-2014-9249 is classified as medium severity due to the potential for remote attackers to read or modify sensitive database information.
How do I fix CVE-2014-9249?
To fix CVE-2014-9249, ensure that the Zenoss Core installation is updated to version 5 or later and secure the database by restricting access to the relevant ports.
What software versions are affected by CVE-2014-9249?
CVE-2014-9249 affects Zenoss Core versions older than 5, including 2.4.0 through 4.2.5.
Can attackers exploit CVE-2014-9249 without authentication?
Yes, attackers can exploit CVE-2014-9249 without authentication if they can connect to the vulnerable ports.
What type of attacks are possible with CVE-2014-9249?
CVE-2014-9249 allows remote attackers to perform unauthorized read or modifications on database information.