Local Code Execution Vulnerability in CouchDB by Vectra Networks
CVE-2018-14889

7.8HIGH

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
21 September 2018

Summary

CouchDB, utilized in Vectra Networks Cognito Brain and Sensor, is susceptible to a local code execution vulnerability that may allow an attacker to execute arbitrary commands on the affected system. This could potentially lead to unauthorized access or manipulation of sensitive data. Users are advised to ensure they are running the latest versions to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.