← All CVEs

CVE-2014-2626

high · 9.4

Directory traversal vulnerability in the toServerObject function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to create files, and consequently execute arbitrary code, via crafted input, aka ZDI-CAN-2024.

9.4
CVSS
19.4%
EPSS (exploit prob.)
97th
EPSS percentile
2014-07-26
Published

AV:N/AC:L/Au:N/C:C/I:C/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
hpnetwork_virtualization8.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-2626