SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-4705

Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S6300, and S6700 series switches; AR150, AR160, AR200, AR1200, AR2200, AR3200, AR530, NetEngine16EX, SRG1300, SRG2300, and SRG3300…

HIGH 7.5EPSS 1.46%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S6300, and S6700 series switches; AR150, AR160, AR200, AR1200, AR2200, AR3200, AR530, NetEngine16EX, SRG1300, SRG2300, and SRG3300 series routers; and WLAN AC6005, AC6605, and ACU2 access controllers allow remote attackers to cause a denial of service (device restart) via a crafted length field in a packet.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
1.46% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
huawei/s9300 firmware · huawei/s9700 firmware · huawei/s7700 firmware · huawei/s5300 firmware · huawei/s5700 firmware · huawei/s6300 firmware · huawei/s6700 firmware · huawei/ar150 firmware · huawei/ar160 firmware · huawei/ar200 firmware · huawei/ar1200 firmware · huawei/ar2200 firmware · huawei/ar3200 firmware · huawei/ar530 firmware · huawei/netengine16ex firmware · huawei/srg1300 firmware · huawei/srg2300 firmware · huawei/srg3300 firmware · huawei/wlan ac6005 firmware · huawei/wlan ac6605 firmware · +1 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.