CVE-2014-4927

UnknownEPSS 11.20%

Last modified

CVE-2014-4927 is a vulnerability of currently unknown severity. Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.. EPSS estimates a 11.20% chance of exploitation in the next 30 days.

Description

Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.

Metrics

EPSS Probability
11.20%

95.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AcmeMicro HttpdAll versions
DlinkDsl2740uAll versions
DlinkDsl2750uAll versions
NetgearMr-Adsl-Dg834All versions
NetgearWgr614v1
NetgearWgr614v2
NetgearWgr614v3
NetgearWgr614v4
NetgearWgr614v5
NetgearWgr614v6
NetgearWgr614v7
NetgearWgr614v8
NetgearWgr614v9

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-4927?
Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.
How severe is CVE-2014-4927?
Severity scoring for CVE-2014-4927 is pending analysis. The EPSS model estimates a 11.20% probability of exploitation in the next 30 days.
How do I fix CVE-2014-4927?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-4927?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST