SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-4094

The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) private_key or (2) public_key parameter in a…

MEDIUM 6.5EPSS 5.63%

Does this matter?

Lower severity and a low EPSS score (5.63%). Track it; it rarely justifies an emergency change on its own.

Description

The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) private_key or (2) public_key parameter in a T/keyManagement request to plain/settings.html, as demonstrated by uploading a Linux ELF file and a shell script.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
5.63% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
imperva/securesphere
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.