CVE-2014-4190

UnknownEPSS 1.50%

Last modified

CVE-2014-4190 is a vulnerability of currently unknown severity. Multiple heap-based buffer overflows in Huawei Campus Series Switches S3700HI, S5700, S6700, S3300HI, S5300, S6300, S9300, S7700, and LSW S9700 with software V200R001 before V200R001SPH013; S5700, S6700, S5300, and S6300 with software V200R002 before V200R002SPH005; S7700, S9300, S9300E, S5300, S5700, S6300, S6700, S2350, S2750, and LSW S9700 with software V200R003 before V200R003SPH005; and S7700, S9300, S9300E, and LSW S9700 with software V200R005 before V200R005C00SPC300 allow remote attackers to cause a denial of service (device restart) via a crafted length field in a packet.. EPSS estimates a 1.50% chance of exploitation in the next 30 days.

Description

Multiple heap-based buffer overflows in Huawei Campus Series Switches S3700HI, S5700, S6700, S3300HI, S5300, S6300, S9300, S7700, and LSW S9700 with software V200R001 before V200R001SPH013; S5700, S6700, S5300, and S6300 with software V200R002 before V200R002SPH005; S7700, S9300, S9300E, S5300, S5700, S6300, S6700, S2350, S2750, and LSW S9700 with software V200R003 before V200R003SPH005; and S7700, S9300, S9300E, and LSW S9700 with software V200R005 before V200R005C00SPC300 allow remote attackers to cause a denial of service (device restart) via a crafted length field in a packet.

Metrics

EPSS Probability
1.50%

70.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiCampus Series Switch Softwarev200r001
HuaweiCampus Lsw S9700All versions
HuaweiCampus S3300hiAll versions
HuaweiCampus S3700hiAll versions
HuaweiCampus S5300All versions
HuaweiCampus S5700All versions
HuaweiCampus S6300All versions
HuaweiCampus S6700All versions
HuaweiCampus S7700All versions
HuaweiCampus S9300All versions
HuaweiCampus Series Switch Softwarev200r005
HuaweiCampus S9300eAll versions
HuaweiCampus Series Switch Softwarev200r003
HuaweiCampus S2350All versions
HuaweiCampus S2750All versions
HuaweiCampus Series Switch Softwarev200r002

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-4190?
Multiple heap-based buffer overflows in Huawei Campus Series Switches S3700HI, S5700, S6700, S3300HI, S5300, S6300, S9300, S7700, and LSW S9700 with software V200R001 before V200R001SPH013; S5700, S6700, S5300, and S6300 with software V200R002 before V200R002SPH005; S7700, S9300, S9300E, S5300, S5700, S6300, S6700, S2350, S2750, and LSW S9700 with software V200R003 before V200R003SPH005; and S7700, S9300, S9300E, and LSW S9700 with software V200R005 before V200R005C00SPC300 allow remote attackers to cause a denial of service (device restart) via a crafted length field in a packet.
How severe is CVE-2014-4190?
Severity scoring for CVE-2014-4190 is pending analysis. The EPSS model estimates a 1.50% probability of exploitation in the next 30 days.
How do I fix CVE-2014-4190?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-4190?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST