CVE-2014-2565
medium
CVSS v3
—
CVSS v2
6.5
VIR risk
6.5
Description
The commandline interface in Blue Coat Content Analysis System (CAS) 1.1 before 1.1.4.2 allows remote administrators to execute arbitrary commands via unspecified vectors, related to "command injection."
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://kb.bluecoat.com/index?page=content&id=SA78&actp=LIST
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| bluecoat | content_analysis_system_software | {"endIncluding":"1.1.2.1"} | |
| bluecoat | content_analysis_system_software | 1.1 | |
| bluecoat | content_analysis_system_software | 1.1.1.1 | |
References
CWEs
CWE-78
Verify integrity in audit chain (admin only). AS-IS.