CVE-2015-2894: Medium severity idera uptime infrastructure monitor vulnerability
Published Dec 31, 2015
·Updated
Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a denial of service (application crash) via format string specifiers.
Affected Software
2 affected components
IDERA Uptime Infrastructure Monitor=6.0
IDERA Uptime Infrastructure Monitor=7.2
Event History
Dec 31, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2894?
CVE-2015-2894 has been classified as a moderate severity vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2015-2894?
To mitigate CVE-2015-2894, update to a non-vulnerable version of Idera Uptime Infrastructure Monitor, ideally versions later than 7.2.
3
What systems are affected by CVE-2015-2894?
CVE-2015-2894 affects Idera Uptime Infrastructure Monitor versions 6.0 and 7.2.
4
What type of attack is associated with CVE-2015-2894?
CVE-2015-2894 is associated with remote denial of service attacks through format string vulnerabilities.
5
Can CVE-2015-2894 be exploited without authentication?
Yes, CVE-2015-2894 can be exploited by remote attackers without requiring authentication.