CVE-2014-4705
Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S6300, and S6700 series switches; AR150, AR160, AR200, AR1200, AR2200, AR3200, AR530, NetEngine16EX, SRG1300, SRG2300, and SRG3300…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S6300, and S6700 series switches; AR150, AR160, AR200, AR1200, AR2200, AR3200, AR530, NetEngine16EX, SRG1300, SRG2300, and SRG3300 series routers; and WLAN AC6005, AC6605, and ACU2 access controllers allow remote attackers to cause a denial of service (device restart) via a crafted length field in a packet.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- huawei/s9300 firmware · huawei/s9700 firmware · huawei/s7700 firmware · huawei/s5300 firmware · huawei/s5700 firmware · huawei/s6300 firmware · huawei/s6700 firmware · huawei/ar150 firmware · huawei/ar160 firmware · huawei/ar200 firmware · huawei/ar1200 firmware · huawei/ar2200 firmware · huawei/ar3200 firmware · huawei/ar530 firmware · huawei/netengine16ex firmware · huawei/srg1300 firmware · huawei/srg2300 firmware · huawei/srg3300 firmware · huawei/wlan ac6005 firmware · huawei/wlan ac6605 firmware · +1 more
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/59349Permissions Required
- http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-345171.htmVendor Advisory
- http://secunia.com/advisories/59349Permissions Required
- http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-345171.htmVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.