VulnerabilityModified
CVE-2014-3081
prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.
MEDIUM 6.3EPSS 4.13%
Does this matter?
Lower severity and a low EPSS score (4.13%). Track it; it rarely justifies an emergency change on its own.
Description
prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.
- CVSS 2.0
- 6.3 MEDIUMAV:N/AC:M/Au:S/C:C/I:N/A:N
- EPSS
- 4.13% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/global console manager 16 firmware · ibm/global console manager 32 firmware
- Source
- psirt@us.ibm.com
References
- http://packetstormsecurity.com/files/127543/IBM-1754-GCM-KVM-Code-Execution-File-Read-XSS.htmlExploit
- http://seclists.org/fulldisclosure/2014/Jul/113
- http://www.exploit-db.com/exploits/34132/Exploit
- http://www.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5095983Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93930
- http://packetstormsecurity.com/files/127543/IBM-1754-GCM-KVM-Code-Execution-File-Read-XSS.htmlExploit
- http://seclists.org/fulldisclosure/2014/Jul/113
- http://www.exploit-db.com/exploits/34132/Exploit
- http://www.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5095983Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93930
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.