CVE-2014-9385

Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger arbitrary code execution via a ZenPack upload, aka ZEN-15388.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 54%
VendorProductVersion
zenosszenoss_core
2.4.0
zenosszenoss_core
2.4.5
zenosszenoss_core
2.5.0
zenosszenoss_core
2.5.1
zenosszenoss_core
2.5.2
zenosszenoss_core
3.0.0
zenosszenoss_core
3.0.1
zenosszenoss_core
3.0.2
zenosszenoss_core
3.0.3
zenosszenoss_core
3.1.0
zenosszenoss_core
3.2.0
zenosszenoss_core
3.2.1
zenosszenoss_core
4.2.0
zenosszenoss_core
4.2.3
zenosszenoss_core
4.2.4
zenosszenoss_core
4.2.5
zenosszenoss_core
5.0.0
zenosszenoss_core
5.0.0:beta_1
zenosszenoss_core
5.0.0:beta_2
zenosszenoss_core
5.0.0:beta_3
𝑥
= Vulnerable software versions