CVE-2014-2378
Published Sep 5, 2014
Last updated 10 years ago
Overview
- Description
- Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.6
- Impact score
- 9.5
- Exploitability score
- 5.5
- Vector string
- AV:A/AC:M/Au:N/C:C/I:C/A:P
Weaknesses
- nvd@nist.gov
- CWE-94
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sensysnetworks:trafficdot:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3DDAF38B-AE0B-4DF3-923B-92715D3D10E9", "versionEndIncluding": "2.10.2" }, { "criteria": "cpe:2.3:a:sensysnetworks:trafficdot:2.8.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D4CD91C-4002-4A30-B533-14CBF1B045CF" }, { "criteria": "cpe:2.3:a:sensysnetworks:trafficdot:2.10.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C685D52A-A97B-4DB7-AE66-F0FFAAAA5B4C" }, { "criteria": "cpe:2.3:a:sensysnetworks:trafficdot:2.10.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "26D5EDCE-D7EC-45E8-8089-ED120E664E0C" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:sensysnetworks:vsn240-f:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBE6EDF8-061E-4390-A09F-8C2D50951C4F" }, { "criteria": "cpe:2.3:h:sensysnetworks:vsn240-t:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "042983FF-7F9D-4A6D-8505-23C2AF8FE7BA" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sensysnetworks:vds:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3EACF484-ADB9-491C-A176-5860345A1E02", "versionEndIncluding": "2.10.0" }, { "criteria": "cpe:2.3:a:sensysnetworks:vds:1.8.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "525BAF30-197B-4EF1-8E2E-358240EDB90B" }, { "criteria": "cpe:2.3:a:sensysnetworks:vds:1.8.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ED1A73FC-7A8C-47B0-BD16-7DBF39F28295" }, { "criteria": "cpe:2.3:a:sensysnetworks:vds:2.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "05B792D3-A6EE-46E6-A461-10ADD327B9C5" }, { "criteria": "cpe:2.3:a:sensysnetworks:vds:2.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E008BB72-F728-4293-9BF0-287572688DDE" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:sensysnetworks:vsn240-f:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EBE6EDF8-061E-4390-A09F-8C2D50951C4F" }, { "criteria": "cpe:2.3:h:sensysnetworks:vsn240-t:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "042983FF-7F9D-4A6D-8505-23C2AF8FE7BA" } ], "operator": "OR" } ], "operator": "AND" } ]