CVE-2014-5073 describes a critical remote command execution vulnerability in vmtadmin.cgi within VMTurbo Operations Manager versions prior to 4.6 build 28657. Attackers can exploit this by injecting shell metacharacters into the fileDate parameter during a DOWN call, allowing arbitrary command execution. With a CVSS score of 7.5, this vulnerability is highly severe, requiring no authentication and having low attack complexity, leading to potential compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, a Metasploit module and ExploitDB entry confirm the existence of public exploit code, indicating a high likelihood of exploitation despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.6CPE matchmatch criteria | cpe:2.3:a:vmturbo:operations_manager:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:vmturbo:operations_manager:4.0:*:*:*:*:*:*:* | ||
4.5CPE matchmatch criteria | cpe:2.3:a:vmturbo:operations_manager:4.5:-:*:*:*:*:*:* | ||
4.5CPE matchmatch criteria | cpe:2.3:a:vmturbo:operations_manager:4.5:1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.