CVE-2014-3440
Last modified
CVE-2014-3440 is a vulnerability of currently unknown severity. The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary commands by leveraging client-system access to upload a log file.. EPSS estimates a 3.31% chance of exploitation in the next 30 days.
Description
The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary commands by leveraging client-system access to upload a log file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Symantec Critical System Protection | 5.2.9 |
| Symantec | Data Center Security | 6.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3440?
How severe is CVE-2014-3440?
How do I fix CVE-2014-3440?
Are you affected by CVE-2014-3440?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
