CVE-2014-1982

CVSS V2 High 10 CVSS V3 None
Description
The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary commands via a direct request to cli.html.
Overview
  • CVE ID
  • CVE-2014-1982
  • Assigner
  • vultures@jpcert.or.jp
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2014-03-31T14:58:35
  • Last Modified Date
  • 2014-03-31T17:57:38
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:alliedtelesis:img646bd_firmware:3.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:alliedtelesis:img646bd:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:alliedtelesis:at-rg634a_firmware:3.3\+:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:alliedtelesis:at-rg634a:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:alliedtelesis:img624a_firmware:3.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:alliedtelesis:img624a:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:alliedtelesis:img616lh_firmware:\+2.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:alliedtelesis:img616lh:-:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:C/I:C/A:C
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • COMPLETE
  • Integrity Impact
  • COMPLETE
  • Availability Impact
  • COMPLETE
  • Base Score
  • 10
  • Severity
  • HIGH
  • Exploitability Score
  • 10
  • Impact Score
  • 10
References
History
Created Old Value New Value Data Type Notes
2022-05-10 10:35:52 Added to TrackCVE
2022-12-01 22:29:37 2014-03-31T14:58Z 2014-03-31T14:58:35 CVE Published Date updated
2022-12-01 22:29:38 2014-03-31T17:57:38 CVE Modified Date updated
2022-12-01 22:29:38 Analyzed Vulnerability Status updated