peter bassill · operator
$ cve CVE-2014-2025 JSON

CVE-2014-2025

9.8
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.97% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2020-01-31
Last modified2026-06-17

Affected (1)

VendorProduct
unitedplanetintrexx

References

→ the Explorer  ·  watch your stack  ·  NVD