CVE-2014-2378

Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.6 UNKNOWN
ADJACENT_NETWORK
MEDIUM
AV:A/AC:M/Au:N/C:C/I:C/A:P
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
sensysnetworkstrafficdot
𝑥
≤ 2.10.2
sensysnetworkstrafficdot
2.8.3
sensysnetworkstrafficdot
2.10.0
sensysnetworkstrafficdot
2.10.1
sensysnetworksvsn240-f
-
sensysnetworksvsn240-t
-
sensysnetworksvds
𝑥
≤ 2.10.0
sensysnetworksvds
1.8.5
sensysnetworksvds
1.8.7
sensysnetworksvds
2.6.3
sensysnetworksvds
2.6.4
sensysnetworksvsn240-f
-
sensysnetworksvsn240-t
-
𝑥
= Vulnerable software versions