CVE-2014-9386
Summary
| CVE | CVE-2014-9386 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-12-15 18:59:28 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zenoss | Zenoss Core | 2.4.0 | All | All | All |
| Application | Zenoss | Zenoss Core | 2.4.5 | All | All | All |
| Application | Zenoss | Zenoss Core | 2.5.0 | All | All | All |
| Application | Zenoss | Zenoss Core | 2.5.1 | All | All | All |
| Application | Zenoss | Zenoss Core | 2.5.2 | All | All | All |
| Application | Zenoss | Zenoss Core | 3.0.0 | All | All | All |
| Application | Zenoss | Zenoss Core | 3.0.1 | All | All | All |
| Application | Zenoss | Zenoss Core | 3.0.2 | All | All | All |
| Application | Zenoss | Zenoss Core | 3.0.3 | All | All | All |
| Application | Zenoss | Zenoss Core | 3.1.0 | All | All | All |
| Application | Zenoss | Zenoss Core | 3.2.0 | All | All | All |
| Application | Zenoss | Zenoss Core | 3.2.1 | All | All | All |
| Application | Zenoss | Zenoss Core | 4.2.0 | All | All | All |
| Application | Zenoss | Zenoss Core | 4.2.3 | All | All | All |
| Application | Zenoss | Zenoss Core | 4.2.4 | All | All | All |
| Application | Zenoss | Zenoss Core | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VU#449452 - جداول بيانات Google | af854a3a-2127-422b-91ae-364da2661108 | docs.google.com | Vendor Advisory |
| Vulnerability Note VU#449452 - Zenoss Core contains multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Zenoss | 2016-03-21 | Zenoss | Addressed in versions 5.0, 4.2.5.SP273, and 4.2.4.SP854 |
There are currently no legacy QID mappings associated with this CVE.