Description
Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-2989 | Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server. |
References
| Link | Providers |
|---|---|
| http://www.kb.cert.org/vuls/id/402020 |
|
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T10:28:46.348Z
Reserved: 2014-04-21T00:00:00.000Z
Link: CVE-2014-2967
No data.
Status : Modified
Published: 2014-07-07T11:01:29.947
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-2967
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD