1

Let's take this CVE for example: http://www.cvedetails.com/cve/CVE-2014-9283/

obtain administrative access via unspecified vectors.

What unspecified vectors means ?

I saw this term in a a lot of CVE.

Does this mean via unspecified factors ? (In the sense that they don't wanna give too much details about it so people can't exploit it easily?)

PS: This is purely for educational purposes.

  • If you say "obtain administrative access by unspecified way" you clearly reveal yourself as *not* a trustworthy security expert on emotional level. – kubanczyk Aug 04 '16 at 08:36

2 Answers2

2

Alternatively (and sadly common) it means the vendor/reporter did not provide Mitre with enough information to write a proper description of the vulnerability.

Kurt
  • 266
  • 1
  • 6
2

An attack vector is a path or means by which an attacker can gain access to a computer or network server in order to deliver a payload or malicious outcome. When it's not specified, it simply means that probably there is a way, but no-one has found one or the vendor does not want the vector to be disclosed yet.

Lucas Kauffman
  • 54,229
  • 17
  • 113
  • 196