10

CVE-2014-7249

Buffer overflow on the Allied Telesis AR440S, AR441S, AR442S, AR745, AR750S, AR750S-DP, AT-8624POE, AT-8624T/2M, AT-8648T/2SP, AT-8748XL, AT-8848, AT-9816GB, AT-9924T, AT-9924Ts, CentreCOM AR415S, CentreCOM AR450S, CentreCOM AR550S, CentreCOM AR570S, CentreCOM 8700SL, CentreCOM 8948XL, CentreCOM 9924SP, CentreCOM 9924T/4SP, Rapier 48i, and SwitchBlade4000 with firmware before 2.9.1-21 allows remote attackers to execute arbitrary code via a crafted HTTP POST request.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AlliedtelesisCentrecom Ar415s Firmware Version <= 2.9.1-20
AlliedtelesisAr442s Firmware Version <= 2.9.1-20
AlliedtelesisAr442s Version-
AlliedtelesisAt-9924t Firmware Version <= 2.9.1-20
AlliedtelesisAt-8848 Firmware Version <= 2.9.1-20
AlliedtelesisRapier 48i Firmware Version <= 2.9.1-20
AlliedtelesisCentrecom Ar450s Firmware Version <= 2.9.1-20
AlliedtelesisAr745 Firmware Version <= 2.9.1-20
AlliedtelesisAr745 Version-
AlliedtelesisAr441s Firmware Version <= 2.9.1-20
AlliedtelesisAr441s Version-
AlliedtelesisCentrecom 9924sp Firmware Version <= 2.9.1-20
AlliedtelesisSwitchblade4000 Firmware Version <= 2.9.1-20
AlliedtelesisAt-8624poe Firmware Version <= 2.9.1-20
AlliedtelesisAt-9816gb Firmware Version <= 2.9.1-20
AlliedtelesisAt-9924ts Firmware Version <= 2.9.1-20
AlliedtelesisAr750s Firmware Version <= 2.9.1-20
AlliedtelesisAr750s Version-
AlliedtelesisCentrecom Ar570s Firmware Version <= 2.9.1-20
AlliedtelesisCentrecom 8948xl Firmware Version <= 2.9.1-20
AlliedtelesisCentrecom 8700sl Firmware Version <= 2.9.1-20
AlliedtelesisAr750s-dp Firmware Version <= 2.9.1-20
AlliedtelesisAr750s-dp Version-
AlliedtelesisCentrecom Ar550s Firmware Version <= 2.9.1-20
AlliedtelesisAt-8748xl Firmware Version <= 2.9.1-20
AlliedtelesisAr440s Firmware Version <= 2.9.1-20
AlliedtelesisAr440s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.45% 0.919
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.