HIGH🇵🇱 Wersja polska

CVE-2014-4705

CVSS 7.5v3.0pub. 2018-01-30upd. 2024-11-21

Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S6300, and S6700 series switches; AR150, AR160, AR200, AR1200, AR2200, AR3200, AR530, NetEngine16EX, SRG1300, SRG2300, and SRG3300 series routers; and WLAN AC6005, AC6605, and ACU2 access controllers allow remote attackers to cause a denial of service (device restart) via a crafted length field in a packet.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Huawei Ar1200

    HW
    Huawei
    all versions
  • Huawei Ar1200 Firmware

    OS
    Huawei
    v200r003c00spc100v200r003c00spc200v200r003c01spc100v200r003c01spc300v200r003c01spc900v200r005c00spc100v200r005c00spc200
  • Huawei Ar150

    HW
    Huawei
    all versions
  • Huawei Ar150 Firmware

    OS
    Huawei
    v200r003c00spc100v200r003c00spc200v200r003c01spc100v200r003c01spc300v200r003c01spc900v200r005c00spc100v200r005c00spc200
  • Huawei Ar160

    HW
    Huawei
    all versions
  • Huawei Ar160 Firmware

    OS
    Huawei
    v200r003c00spc100v200r003c00spc200v200r003c01spc100v200r003c01spc300v200r003c01spc900v200r005c00spc100v200r005c00spc200
  • Huawei Ar200

    HW
    Huawei
    all versions
  • Huawei Ar200 Firmware

    OS
    Huawei
    v200r003c00spc100v200r003c00spc200v200r003c01spc100v200r003c01spc300v200r003c01spc900v200r005c00spc100v200r005c00spc200
  • Huawei Ar2200

    HW
    Huawei
    all versions
  • Huawei Ar2200 Firmware

    OS
    Huawei
    v200r003c00spc100v200r003c00spc200v200r003c01spc100v200r003c01spc300v200r003c01spc900v200r005c00spc100v200r005c00spc200
  • Huawei Ar3200

    HW
    Huawei
    all versions
  • Huawei Ar3200 Firmware

    OS
    Huawei
    v200r003c00spc100v200r003c00spc200v200r003c01spc100v200r003c01spc300v200r003c01spc900v200r005c00spc100v200r005c00spc200
  • Huawei Ar530

    HW
    Huawei
    all versions
  • Huawei Ar530 Firmware

    OS
    Huawei
    v200r003c00spc100v200r003c00spc200v200r003c01spc100v200r003c01spc300v200r003c01spc900v200r005c00spc100v200r005c00spc200
  • Huawei Netengine16ex

    HW
    Huawei
    all versions
  • Huawei Netengine16ex Firmware

    OS
    Huawei
    v200r003c00spc100v200r003c00spc200v200r003c01spc100v200r003c01spc300v200r003c01spc900v200r005c00spc100v200r005c00spc200
  • Huawei S5300

    HW
    Huawei
    all versions
  • Huawei S5300 Firmware

    OS
    Huawei
    v200r001c00spc300v200r002c00spc100v200r003c00spc300
  • Huawei S5700

    HW
    Huawei
    all versions
  • Huawei S5700 Firmware

    OS
    Huawei
    v200r001c00spc300v200r002c00spc100v200r003c00spc300
  • Huawei S6300

    HW
    Huawei
    all versions
  • Huawei S6300 Firmware

    OS
    Huawei
    v200r001c00spc300v200r002c00spc100v200r003c00spc300
  • Huawei S6700

    HW
    Huawei
    all versions
  • Huawei S6700 Firmware

    OS
    Huawei
    v200r001c00spc300v200r002c00spc100v200r003c00spc300
  • Huawei S7700

    HW
    Huawei
    all versions
  • Huawei S7700 Firmware

    OS
    Huawei
    v200r001c00spc300v200r002c00spc100v200r003c00spc500
  • Huawei S9300

    HW
    Huawei
    all versions
  • Huawei S9300 Firmware

    OS
    Huawei
    v200r001c00spc300v200r002c00spc100v200r003c00spc500
  • Huawei S9700

    HW
    Huawei
    all versions
  • Huawei S9700 Firmware

    OS
    Huawei
    v200r001c00spc300v200r002c00spc100v200r003c00spc500
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoSMemory
CWE
References

Related vulnerabilities

CVE-2020-9068CRITICAL9.8PL ✓same product

Nieprawidłowe uwierzytelnienie w Huawei AR3200 — obejście autoryzacji

CVE-2017-17301CRITICAL9.8PL ✓same product

Słaba kryptografia w produktach Huawei — fałszowanie certyfikatów RSA

CVE-2016-6206CRITICAL9.8PL ✓same product

RCE/DoS w routerach Huawei AR3200 poprzez spreparowany pakiet

CVE-2021-37129HIGH7.5same product

There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a functi...

CVE-2021-22357HIGH7.5same product

There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages due...