SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-2543

Buffer overflow in the Rendezvous Daemon (rvd), Rendezvous Routing Daemon (rvrd), Rendezvous Secure Daemon (rvsd), and Rendezvous Secure Routing Daemon (rvsrd) in TIBCO Rendezvous before 8.4.2, Messaging Appliance before 8.7.1, and Substation ES before…

HIGH 7.5EPSS 4.01%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Buffer overflow in the Rendezvous Daemon (rvd), Rendezvous Routing Daemon (rvrd), Rendezvous Secure Daemon (rvsd), and Rendezvous Secure Routing Daemon (rvsrd) in TIBCO Rendezvous before 8.4.2, Messaging Appliance before 8.7.1, and Substation ES before 2.8.1 allows remote attackers to execute arbitrary code by leveraging access to a directly connected client and transmitting crafted data.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
4.01% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
tibco/rendezvous · tibco/substantiation es · tibco/messaging appliance
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.