CVE-2018-14804: Code Injection
Published Sep 27, 2018
·Updated
Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.
Affected Software
1 affected component
Emerson AMS Device Manager>=12.0<=13.5
Event History
Oct 1, 2018
CVE Published
03:29 PM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-14804?
CVE-2018-14804 has been rated with a critical severity level due to its potential for arbitrary remote code execution.
2
How do I fix CVE-2018-14804?
To fix CVE-2018-14804, users should update Emerson AMS Device Manager to a patched version beyond 13.5.
3
What versions are affected by CVE-2018-14804?
CVE-2018-14804 affects Emerson AMS Device Manager versions from 12.0 to 13.5.
4
What type of vulnerability is CVE-2018-14804?
CVE-2018-14804 is classified as a remote code execution vulnerability.
5
Can CVE-2018-14804 be exploited remotely?
Yes, CVE-2018-14804 can be exploited remotely by executing specially crafted scripts.