CVE-2014-2332

Current Description

Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, related to "Insecure Direct Object References." NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330.

Basic Data

PublishedAugust 31, 2015
Last ModifiedSeptember 01, 2015
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeCWE-20
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:L/Au:S/C:N/I:P/A:P
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationSINGLE
CVSS 2 - Confidentiality ImpactNONE
CVSS 2 - Availability ImpactPARTIAL
CVSS 2 - Base Score5.5
SeverityMEDIUM
Exploitability Score8.0
Impact Score4.9
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationCheck Mk ProjectCheck Mk********1.2.2
    2.3ApplicationCheck Mk ProjectCheck Mk********1.2.3

Vulnerable Software List

VendorProductVersions
Check Mk Project Check Mk *

References

NameSourceURLTags
20140324 Deutsche Telekom CERT Advisory [DTC-A-20140324-002] vulnerabilities in check_mkhttp://www.securityfocus.com/archive/1/531594BUGTRAQ
20140328 Deutsche Telekom CERT Advisory [DTC-A-20140324-002] update140328http://www.securityfocus.com/archive/1/531656BUGTRAQ