CVE-2014-2960
high
CVSS v3
7.5
CVSS v2
5.0
VIR risk
7.5
Description
Vision Critical before 2014-05-30 allows attackers to read arbitrary files via unspecified vectors, as demonstrated by image files and configuration files.
Predictions
Exploit likelihood
83%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cret@cert.org — https://www.visioncritical.com/customer-advisory-vision-critical-cto/
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| visioncritical | vision_critical | {"endIncluding":"2014-05-30"} | |
References
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.