CVE-2015-0525: OS Command Injection
Published Mar 12, 2015
·Updated
The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Affected Software
2 affected components
EMC Secure Remote Services=3.02
EMC Secure Remote Services=3.03
Event History
Mar 12, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0525?
CVE-2015-0525 is classified as a critical vulnerability due to its ability to allow remote attackers to execute arbitrary OS commands.
2
How do I fix CVE-2015-0525?
To mitigate CVE-2015-0525, upgrade EMC Secure Remote Services Virtual Edition to version 3.04 or later.
3
What software is affected by CVE-2015-0525?
CVE-2015-0525 affects EMC Secure Remote Services versions 3.02 and 3.03.
4
Can CVE-2015-0525 be exploited remotely?
Yes, CVE-2015-0525 can be exploited remotely by attackers with access to the Gateway Provisioning service.
5
What are the potential consequences of CVE-2015-0525?
Exploitation of CVE-2015-0525 could lead to unauthorized system access and the execution of arbitrary commands.