CVE-2014-4706

UnknownEPSS 0.74%

Last modified

CVE-2014-4706 is a vulnerability of currently unknown severity. Huawei Campus S3700HI with software V200R001C00SPC300; Campus S5700 with software V200R002C00SPC100; Campus S7700 with software V200R003C00SPC300,V200R003C00SPC500; LSW S9700 with software V200R001C00SPC300,V200R003C00SPC300,V200R003C00SPC500; S2350 with software V200R003C00SPC300; S2750 with software V200R003C00SPC300; S5300 with software V200R001C00SPC300,V200R002C00SPC100,V200R003C00SPC300; S5700 with software V200R001C00SPC300,V200R003C00SPC300; S6300 with software V200R001C00SPC300,V200R002C00SPC100,V200R003C00SPC300; S6700 S3300HI with software V200R001C00SPC300,V200R002C00SPC100,V200R003C00SPC300; S7700 with software V200R001C00SPC300; S9300 with software V200R001C00SPC300,V200R003C00SPC300,V200R003C00SPC500; S9300E with software V200R003C00SPC300,V200R003C00SPC500 allow attackers to keep sending malformed packets to cause a denial of service (DoS) attack, aka a heap overflow.. EPSS estimates a 0.74% chance of exploitation in the next 30 days.

Description

Huawei Campus S3700HI with software V200R001C00SPC300; Campus S5700 with software V200R002C00SPC100; Campus S7700 with software V200R003C00SPC300,V200R003C00SPC500; LSW S9700 with software V200R001C00SPC300,V200R003C00SPC300,V200R003C00SPC500; S2350 with software V200R003C00SPC300; S2750 with software V200R003C00SPC300; S5300 with software V200R001C00SPC300,V200R002C00SPC100,V200R003C00SPC300; S5700 with software V200R001C00SPC300,V200R003C00SPC300; S6300 with software V200R001C00SPC300,V200R002C00SPC100,V200R003C00SPC300; S6700 S3300HI with software V200R001C00SPC300,V200R002C00SPC100,V200R003C00SPC300; S7700 with software V200R001C00SPC300; S9300 with software V200R001C00SPC300,V200R003C00SPC300,V200R003C00SPC500; S9300E with software V200R003C00SPC300,V200R003C00SPC500 allow attackers to keep sending malformed packets to cause a denial of service (DoS) attack, aka a heap overflow.

Metrics

EPSS Probability
0.74%

49.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiCampus S3700hi Firmwarev200r001c00spc300
HuaweiS5700 Firmwarev200r001c00spc300
HuaweiS6700 Firmwarev200r001c00spc300
HuaweiS3300hi Firmwarev200r001c00spc300
HuaweiS5300 Firmwarev200r001c00spc300
HuaweiS6300 Firmwarev200r001c00spc300
HuaweiS9300 Firmwarev200r001c00spc300
HuaweiS7700 Firmwarev200r001c00spc300
HuaweiLsw S9700 Firmwarev200r001c00spc300
HuaweiCampus S5700 Firmwarev200r002c00spc100
HuaweiS6700 Firmwarev200r002c00spc100
HuaweiS5300 Firmwarev200r002c00spc100
HuaweiS6300 Firmwarev200r002c00spc100
HuaweiCampus S7700 Firmwarev200r003c00spc300
HuaweiS9300 Firmwarev200r003c00spc300
HuaweiS9300e Firmwarev200r003c00spc300
HuaweiS5300 Firmwarev200r003c00spc300
HuaweiS5700 Firmwarev200r003c00spc300
HuaweiS6300 Firmwarev200r003c00spc300
HuaweiS6700 Firmwarev200r003c00spc300
HuaweiS2350 Firmwarev200r003c00spc300
HuaweiS2750 Firmwarev200r003c00spc300
HuaweiLsw S9700 Firmwarev200r003c00spc300
HuaweiCampus S7700 Firmwarev200r003c00spc500
HuaweiS9300 Firmwarev200r003c00spc500
HuaweiS9300e Firmwarev200r003c00spc500
HuaweiLsw S9700 Firmwarev200r003c00spc500

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-4706?
Huawei Campus S3700HI with software V200R001C00SPC300; Campus S5700 with software V200R002C00SPC100; Campus S7700 with software V200R003C00SPC300,V200R003C00SPC500; LSW S9700 with software V200R001C00SPC300,V200R003C00SPC300,V200R003C00SPC500; S2350 with software V200R003C00SPC300; S2750 with software V200R003C00SPC300; S5300 with software V200R001C00SPC300,V200R002C00SPC100,V200R003C00SPC300; S5700 with software V200R001C00SPC300,V200R003C00SPC300; S6300 with software V200R001C00SPC300,V200R002C00SPC100,V200R003C00SPC300; S6700 S3300HI with software V200R001C00SPC300,V200R002C00SPC100,V200R003C00SPC300; S7700 with software V200R001C00SPC300; S9300 with software V200R001C00SPC300,V200R003C00SPC300,V200R003C00SPC500; S9300E with software V200R003C00SPC300,V200R003C00SPC500 allow attackers to keep sending malformed packets to cause a denial of service (DoS) attack, aka a heap overflow.
How severe is CVE-2014-4706?
Severity scoring for CVE-2014-4706 is pending analysis. The EPSS model estimates a 0.74% probability of exploitation in the next 30 days.
How do I fix CVE-2014-4706?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-4706?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST