PT-2015-4358 · Palo Alto Networks+2 · Pan-Os+2

CVE-2014-9708

·

Publicado

2015-03-31

·

Atualizado

2023-06-22

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Embedthis Appweb versions 4.6.6 and earlier, 5.x before 5.2.1 PAN-OS versions prior to 5.0.20 PAN-OS versions prior to 5.1.13 PAN-OS versions prior to 6.0.15 PAN-OS versions prior to 6.1.15 PAN-OS versions prior to 7.0.11 PAN-OS versions prior to 7.1.6
Description The issue allows remote attackers to cause a denial of service via a Range header with an empty value, as demonstrated by "Range: x=,". This pre-authenticated denial-of-service attack could disrupt the web management interface.
Recommendations For Embedthis Appweb versions 4.6.6 and earlier, update to version 4.6.6 or later. For Embedthis Appweb 5.x before 5.2.1, update to version 5.2.1 or later. For PAN-OS versions prior to 5.0.20, update to version 5.0.20 or later. For PAN-OS versions prior to 5.1.13, update to version 5.1.13 or later. For PAN-OS versions prior to 6.0.15, update to version 6.0.15 or later. For PAN-OS versions prior to 6.1.15, update to version 6.1.15 or later. For PAN-OS versions prior to 7.0.11, update to version 7.0.11 or later. For PAN-OS versions prior to 7.1.6, update to version 7.1.6 or later. As a temporary workaround, consider restricting access to the web management interface until a patch is available.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9708

Produtos afetados

Appweb
Junos
Pan-Os