vendor:
Skybox View Appliances
by:
Luigi Vezzoso
7,5
CVSS
HIGH
Bypass Authentication
287
CWE
Product Name: Skybox View Appliances
Affected Version From: 6.3.33-2.14
Affected Version To: 6.4.46-2.57
Patch Exists: YES
Related CWE: CVE-2014-2085
CPE: a:skybox_security:skybox_view
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Centos 6.4 kernel 2.6.32
2014
SKYBOX Security – DDOS
A vulnerability has been found in some Skybox View Appliances’ Admin interfaces which would allow a potential malicious party to bypass the authentication mechanism and execute reboot and/or shutdown of appliance self.
Mitigation:
Please refer to the vendor security advisor: Security Advisory 2014-3-25-1