{"api_version":"1","generated_at":"2026-07-23T19:55:45+00:00","cve":"CVE-2014-2959","urls":{"html":"https://cve.report/CVE-2014-2959","api":"https://cve.report/api/cve/CVE-2014-2959.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-2959","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-2959"},"summary":{"title":"CVE-2014-2959","description":"logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter.","state":"PUBLISHED","assigner":"certcc","published_at":"2014-06-02 19:55:03","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-78","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:P/A:P","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/59019","name":"http://secunia.com/advisories/59019","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA59019 - Dell PowerVault ML6000 logViewer.htm Command Injection Vulnerabilty - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/67751","name":"http://www.securityfocus.com/bid/67751","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Dell PowerVault ML6000 and Quantum Scalar i500 CVE-2014-2959 Remote Command Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/124908","name":"http://www.kb.cert.org/vuls/id/124908","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"Vulnerability Note VU#124908 - Dell ML6000 and Quantum Scalar i500 tape backup system command injection vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-2959","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2959","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"2959","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"dell","cpe5":"powervault_ml6000","cpe6":"32u","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2959","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"dell","cpe5":"powervault_ml6000","cpe6":"41u","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2959","vulnerable":"1","versionEndIncluding":"i8.2.0.1_\\(641g.gs003\\)","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"dell","cpe5":"powervault_ml6000_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2959","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"quantum","cpe5":"scalar_i500","cpe6":"14u","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2959","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"quantum","cpe5":"scalar_i500","cpe6":"23u","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2959","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"quantum","cpe5":"scalar_i500","cpe6":"5u","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2959","vulnerable":"1","versionEndIncluding":"i8.2.2.1_\\(646g.gs002\\)","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"quantum","cpe5":"scalar_i500_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:28:46.358Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"67751","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/67751"},{"name":"VU#124908","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/124908"},{"name":"59019","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/59019"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-05-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-06-20T12:57:00.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"67751","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/67751"},{"name":"VU#124908","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/124908"},{"name":"59019","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/59019"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2014-2959","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"67751","refsource":"BID","url":"http://www.securityfocus.com/bid/67751"},{"name":"VU#124908","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/124908"},{"name":"59019","refsource":"SECUNIA","url":"http://secunia.com/advisories/59019"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2014-2959","datePublished":"2014-06-02T19:00:00.000Z","dateReserved":"2014-04-21T00:00:00.000Z","dateUpdated":"2024-08-06T10:28:46.358Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-06-02 19:55:03","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-78","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:P/A:P","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":8.5,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dell:powervault_ml6000_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"i8.2.0.1_\\(641g.gs003\\)","matchCriteriaId":"4DFB91B9-A601-4F22-A1D2-D9DD5C8F9385"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:dell:powervault_ml6000:32u:*:*:*:*:*:*:*","matchCriteriaId":"136C9AB1-37AE-43EE-BAAC-39277789B734"},{"vulnerable":true,"criteria":"cpe:2.3:h:dell:powervault_ml6000:41u:*:*:*:*:*:*:*","matchCriteriaId":"33A96FD1-2005-41BE-ACE5-33AC136F7206"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:quantum:scalar_i500_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"i8.2.2.1_\\(646g.gs002\\)","matchCriteriaId":"2E26485A-B28F-42DF-8650-59A7D7C9D554"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:quantum:scalar_i500:5u:*:*:*:*:*:*:*","matchCriteriaId":"C6AA8B64-A78C-4B51-B29B-21CF2AEF9484"},{"vulnerable":true,"criteria":"cpe:2.3:h:quantum:scalar_i500:14u:*:*:*:*:*:*:*","matchCriteriaId":"E6FFB7DA-15EB-4053-9440-A30F8E434F5C"},{"vulnerable":true,"criteria":"cpe:2.3:h:quantum:scalar_i500:23u:*:*:*:*:*:*:*","matchCriteriaId":"C39DFB77-7945-4CA0-9B66-AF3908FE515D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"2959","Ordinal":"1","Title":"CVE-2014-2959","CVE":"CVE-2014-2959","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"2959","Ordinal":"1","NoteData":"logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter.","Type":"Description","Title":"CVE-2014-2959"},{"CveYear":"2014","CveId":"2959","Ordinal":"2","NoteData":"2014-06-02","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"2959","Ordinal":"3","NoteData":"2014-06-20","Type":"Other","Title":"Modified"}]}}}