CVE-2014-9575: Vdgsecurity Vdg Sense

Medium severity, CVSS 6.4. EPSS: 2.4% chance of exploitation in the next 30 days.

VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin settings, via an encoded : (colon) character in the Authorization HTTP header.

Affected products

Published 2015-01-08. Last modified 2026-06-17.