Overview
SearchBlox contains multiple vulnerabilities that can allow an unauthenticated attacker to overwrite critical data on the filesystem, read cleartext user credentials, or execute arbitrary code on a vulnerable system.
Description
SearchBlox versions 7.4 Build 1 and older contain multiple vulnerabilities that allow an unauthenticated attacker to compromise the integrity of the system and the confidentiality of its data. Specifically: CWE-77: Command Injection - CVE-2013-3590 |
Impact
An unauthenticated remote attacker could compromise the confidentiality of the system's data, perform arbitrary code execution, overwrite data on the filesystem with the application's privileges, and compromise the availability of the system. |
Solution
Apply an Update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9.7 | AV:N/AC:L/Au:N/C:C/I:P/A:C |
Temporal | 8 | E:F/RL:OF/RC:C |
Environmental | 2.1 | CDP:LM/TD:L/CR:M/IR:M/AR:M |
References
Acknowledgements
Thanks to Ricky Roane Jr. for reporting this vulnerability.
This document was written by Todd Lewellen.
Other Information
CVE IDs: | CVE-2013-3590, CVE-2013-3597, CVE-2013-3598 |
Date Public: | 2013-08-12 |
Date First Published: | 2013-08-23 |
Date Last Updated: | 2013-08-23 14:18 UTC |
Document Revision: | 19 |