CVE-2014-6258 describes a denial-of-service vulnerability in Zenoss Core through 5 Beta 3, where an unspecified endpoint can be exploited to cause high CPU consumption through arbitrary regular-expression match attempts. This vulnerability has a CVSS score of 5.0, indicating a medium severity, and can be exploited remotely with low attack complexity, leading to a partial denial of service. There is no evidence of active exploitation, nor are there publicly available Metasploit or Nuclei exploits. Despite limited community discussion and media coverage, SecurityWeek did report on numerous Zenoss Core vulnerabilities, including this one.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.0.0CPE matchmatch criteria | cpe:2.3:a:zenoss:zenoss_core:*:beta_3:*:*:*:*:*:* | ||
2.4.0CPE matchmatch criteria | cpe:2.3:a:zenoss:zenoss_core:2.4.0:*:*:*:*:*:*:* | ||
2.4.5CPE matchmatch criteria | cpe:2.3:a:zenoss:zenoss_core:2.4.5:*:*:*:*:*:*:* | ||
2.5.0CPE matchmatch criteria | cpe:2.3:a:zenoss:zenoss_core:2.5.0:*:*:*:*:*:*:* | ||
2.5.1CPE matchmatch criteria | cpe:2.3:a:zenoss:zenoss_core:2.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.