Lucene search

K
cve[email protected]CVE-2014-9284
HistoryJun 09, 2015 - 12:59 a.m.

CVE-2014-9284

2015-06-0900:59:00
CWE-78
web.nvd.nist.gov
22
buffalo
router
remote authentication
os command execution
vulnerability
cve-2014-9284

7.7 High

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

45.8%

The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 and earlier, WEX-300 1.60 and earlier, and BHR-4GRV2 1.04 and earlier routers allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.

Affected configurations

NVD
Node
buffalotechwsr-600dhp_firmwareRange1.60
AND
buffalotechwsr-600dhpMatch-
Node
buffalotechwhr-300hp2_firmwareRange1.60
AND
buffalotechwhr-300hp2Match-
Node
buffalotechwhr-1166dhp_firmwareRange1.60
AND
buffalotechwhr-1166dhpMatch-
Node
buffalotechbhr-4grv2Match-
AND
buffalotechbhr-4grv2_firmwareRange1.04
Node
buffalotechwmr-300Match-
AND
buffalotechwmr-300_firmwareRange1.60
Node
buffalotechwex-300Match-
AND
buffalotechwex-300_firmwareRange1.60
Node
buffalotechwhr-600dMatch-
AND
buffalotechwhr-600d_firmwareRange1.60

7.7 High

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

45.8%

Related for CVE-2014-9284