Description
Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-2989 | Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server. |
References
| Link | Providers |
|---|---|
| http://www.kb.cert.org/vuls/id/402020 |
|
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T10:28:46.348Z
Reserved: 2014-04-21T00:00:00.000Z
Link: CVE-2014-2967
No data.
Status : Modified
Published: 2014-07-07T11:01:29.947
Modified: 2026-06-17T00:07:24.930
Link: CVE-2014-2967
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
EUVD