HTTP: IBM GCM CVE-2014-3085 Remote Code Execution

This signature detects attempts to exploit a known vulnerability against IBM GCM. A successful attack can lead to arbitrary code execution.

Extended Description

systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter.

Affected Products

Ibm global_console_manager_32_firmware

References

CVE: CVE-2014-3085

Short Name
HTTP:MISC:GCM-CVE-2014-3085-RCE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2014-3085 Code Execution GCM IBM Remote
Release Date
04/13/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Ibm

CVSS Score

7.1

Found a potential security threat?