March 25, 2022 · Applied Cybernetics Group
CVE-2014-6287 — Rejetto HTTP File Server (HFS)
Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
- Added to KEV
2022-03-25- Federal due date
2022-04-15- Vendor
- Rejetto
- Product
- HTTP File Server (HFS)
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2014-6287
CISA short description
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
Required action
Apply updates per vendor instructions.