{ "schema_version": "1.4.0", "id": "GHSA-rpj9-vvgv-g3hf", "modified": "2022-05-17T04:37:34Z", "published": "2022-05-17T04:37:34Z", "aliases": [ "CVE-2014-2378" ], "details": "Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-2378" }, { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSA-14-247-01" } ], "database_specific": { "cwe_ids": [ "CWE-94" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2014-09-05T17:55:00Z" } }