PatchSiren cyber security CVE debrief
CVE-2014-6287 Rejetto CVE debrief
CVE-2014-6287 is listed by CISA in the Known Exploited Vulnerabilities catalog as a remote code execution issue affecting Rejetto HTTP File Server (HFS). CISA added the vulnerability on 2022-03-25 and set a remediation due date of 2022-04-15. The supplied guidance is to apply updates per vendor instructions.
- Vendor
- Rejetto
- Product
- HTTP File Server (HFS)
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-03-25
- Original CVE updated
- 2022-03-25
- Advisory published
- 2022-03-25
- Advisory updated
- 2022-03-25
Who should care
Organizations that use Rejetto HTTP File Server (HFS), along with vulnerability management, endpoint/security operations, and incident response teams responsible for prioritizing KEV-listed issues.
Technical summary
Official records identify this issue as a remote code execution vulnerability in Rejetto HTTP File Server (HFS). The CISA KEV record classifies it as a known exploited vulnerability and directs affected users to apply vendor updates.
Defensive priority
High — CISA has listed this CVE in KEV, which makes it a priority remediation item with a defined due date.
Recommended defensive actions
- Identify any systems running Rejetto HTTP File Server (HFS).
- Apply updates per vendor instructions as directed by CISA.
- Track remediation against the KEV due date of 2022-04-15 if still outstanding.
- Verify exposure and remove or disable unused instances where appropriate.
- Document completion in vulnerability management and risk tracking systems.
Evidence notes
This debrief is based on the supplied CISA KEV record and official references only. The source item identifies CVE-2014-6287 as "Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability," with dateAdded 2022-03-25, dueDate 2022-04-15, and requiredAction "Apply updates per vendor instructions." The source also notes unknown ransomware campaign use. No additional exploit mechanics or version details were provided in the corpus.
Official resources
-
CVE-2014-6287 CVE record
CVE.org
-
CVE-2014-6287 NVD detail
NVD
-
CISA Known Exploited Vulnerabilities catalog
CISA - Apply updates per vendor instructions.
-
Source item URL
cisa_kev
CISA lists this CVE in its Known Exploited Vulnerabilities catalog. The supplied record indicates unknown ransomware campaign use and directs affected parties to apply vendor updates.