CVE-2014-2959
Summary
| CVE | CVE-2014-2959 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-06-02 19:55:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:C/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dell | Powervault Ml6000 | 32u | All | All | All |
| Hardware | Dell | Powervault Ml6000 | 41u | All | All | All |
| Operating System | Dell | Powervault Ml6000 Firmware | All | All | All | All |
| Hardware | Quantum | Scalar I500 | 14u | All | All | All |
| Hardware | Quantum | Scalar I500 | 23u | All | All | All |
| Hardware | Quantum | Scalar I500 | 5u | All | All | All |
| Operating System | Quantum | Scalar I500 Firmware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA59019 - Dell PowerVault ML6000 logViewer.htm Command Injection Vulnerabilty - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Dell PowerVault ML6000 and Quantum Scalar i500 CVE-2014-2959 Remote Command Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Vulnerability Note VU#124908 - Dell ML6000 and Quantum Scalar i500 tape backup system command injection vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.