CVE-2014-4190
Last modified
CVE-2014-4190 is a vulnerability of currently unknown severity. Multiple heap-based buffer overflows in Huawei Campus Series Switches S3700HI, S5700, S6700, S3300HI, S5300, S6300, S9300, S7700, and LSW S9700 with software V200R001 before V200R001SPH013; S5700, S6700, S5300, and S6300 with software V200R002 before V200R002SPH005; S7700, S9300, S9300E, S5300, S5700, S6300, S6700, S2350, S2750, and LSW S9700 with software V200R003 before V200R003SPH005; and S7700, S9300, S9300E, and LSW S9700 with software V200R005 before V200R005C00SPC300 allow remote attackers to cause a denial of service (device restart) via a crafted length field in a packet.. EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
Multiple heap-based buffer overflows in Huawei Campus Series Switches S3700HI, S5700, S6700, S3300HI, S5300, S6300, S9300, S7700, and LSW S9700 with software V200R001 before V200R001SPH013; S5700, S6700, S5300, and S6300 with software V200R002 before V200R002SPH005; S7700, S9300, S9300E, S5300, S5700, S6300, S6700, S2350, S2750, and LSW S9700 with software V200R003 before V200R003SPH005; and S7700, S9300, S9300E, and LSW S9700 with software V200R005 before V200R005C00SPC300 allow remote attackers to cause a denial of service (device restart) via a crafted length field in a packet.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Campus Series Switch Software | v200r001 |
| Huawei | Campus Lsw S9700 | All versions |
| Huawei | Campus S3300hi | All versions |
| Huawei | Campus S3700hi | All versions |
| Huawei | Campus S5300 | All versions |
| Huawei | Campus S5700 | All versions |
| Huawei | Campus S6300 | All versions |
| Huawei | Campus S6700 | All versions |
| Huawei | Campus S7700 | All versions |
| Huawei | Campus S9300 | All versions |
| Huawei | Campus Series Switch Software | v200r005 |
| Huawei | Campus S9300e | All versions |
| Huawei | Campus Series Switch Software | v200r003 |
| Huawei | Campus S2350 | All versions |
| Huawei | Campus S2750 | All versions |
| Huawei | Campus Series Switch Software | v200r002 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-4190?
How severe is CVE-2014-4190?
How do I fix CVE-2014-4190?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-4171mm/shmem.c in the Linux kernel through 3.15.1 does not prope…
- CVE-2014-4172A URL parameter injection vulnerability was found in the bac…9.8
- CVE-2014-4174wiretap/libpcap.c in the libpcap file parser in Wireshark 1.…
- CVE-2014-4187Cross-site scripting (XSS) vulnerability in signup.php in Cl…
- CVE-2014-4188Cross-site request forgery (CSRF) vulnerability in Hitachi T…
- CVE-2014-4189Cross-site scripting (XSS) vulnerability in Hitachi Tuning M…
- CVE-2014-4191The TLS implementation in EMC RSA BSAFE-C Toolkits (aka Shar…
- CVE-2014-4192The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits …
- CVE-2014-4193The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka S…
- CVE-2014-4194SQL injection vulnerability in zero_transact_article.php in …
- CVE-2014-4195Cross-site scripting (XSS) vulnerability in zero_view_articl…
- CVE-2014-4196Cross-site scripting (XSS) vulnerability in bsi.dll in Bank …6.1
Are you affected by CVE-2014-4190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
