CVE-2014-8684
Seagate Business NAS - Remote Command Execution
Severity Score
9.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.
CodeIgniter antes de la versión 3.0 y Kohana 3.2.3 y anteriores y en versiones 3.3.x hasta la 3.3.2 facilita que los atacantes remotos suplanten cookies de sesión y lleven a cabo ataques de inyección de objetos PHP. Esto se realizaría por medio de operadores estándar de comparación de strings para comparar hashes criptográficos.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-11-09 CVE Reserved
- 2015-03-02 CVE Published
- 2015-03-04 First Exploit
- 2023-07-05 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (7)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/36264 | 2015-03-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Codeigniter Search vendor "Codeigniter" | Codeigniter Search vendor "Codeigniter" for product "Codeigniter" | <= 2.2.6 Search vendor "Codeigniter" for product "Codeigniter" and version " <= 2.2.6" | - |
Affected
| ||||||
Kohanaframework Search vendor "Kohanaframework" | Kohana Search vendor "Kohanaframework" for product "Kohana" | 3.2.3 Search vendor "Kohanaframework" for product "Kohana" and version "3.2.3" | - |
Affected
| ||||||
Kohanaframework Search vendor "Kohanaframework" | Kohana Search vendor "Kohanaframework" for product "Kohana" | 3.3.0 Search vendor "Kohanaframework" for product "Kohana" and version "3.3.0" | - |
Affected
| ||||||
Kohanaframework Search vendor "Kohanaframework" | Kohana Search vendor "Kohanaframework" for product "Kohana" | 3.3.1 Search vendor "Kohanaframework" for product "Kohana" and version "3.3.1" | - |
Affected
|