CVE-2014-4875
Last modified
CVE-2014-4875 is a vulnerability of currently unknown severity. CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.. EPSS estimates a 2.06% chance of exploitation in the next 30 days.
Description
CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Server (BOSS) DB2 database credentials by leveraging knowledge of this key in conjunction with bossinfo.pro read access.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Toshiba | Chec | <= 6.6 |
| Toshiba | Chec | 6.7 |
References
- http://www.kb.cert.org/vuls/id/301788Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/JLAD-9X4SPNThird Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/301788Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/JLAD-9X4SPNThird Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-4875?
How severe is CVE-2014-4875?
How do I fix CVE-2014-4875?
Are you affected by CVE-2014-4875?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
