Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-14948

Опубликовано: 14 окт. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:dlink:dir-868l_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-868l:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:dlink:dir-890l_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-890l:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:dlink:dir-885l_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-885l:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:dlink:dir-895l_firmware:1.13b03:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-895l:-:*:*:*:*:*:*:*
Конфигурация 5

Одновременно

cpe:2.3:o:dlink:dir-880l_firmware:1.08b04:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-880l:-:*:*:*:*:*:*:*
Конфигурация 6

Одновременно

cpe:2.3:o:dlink:dir-895r_firmware:1.13b03:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-895r:-:*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.03012
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-120

Связанные уязвимости

github
больше 3 лет назад

Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.

EPSS

Процентиль: 86%
0.03012
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-120