CVE-2014-2025

CRITICAL

Unspecified Third Party Tool <6.0 - RCE

Title source: llm
STIX 2.1

Description

Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors.

Scores

CVSS v3 9.8
EPSS 0.0901
EPSS Percentile 92.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
unitedplanet/intrexx 5.2
unitedplanet/intrexx 6.0
Published Jan 31, 2020
Tracked Since Feb 18, 2026