CVE-2019-14894
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console could use this flaw to execute arbitrary shell commands on the CloudForms server as root.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.08% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-78
- Affected
- redhat/cloudforms management engine
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14894Issue Tracking, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14894Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.