CVE-2014-8244

CVSS V2 High 7.5 CVSS V3 None
Description
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain sensitive information or modify data via a JNAP action in a JNAP/ HTTP request.
Overview
  • CVE ID
  • CVE-2014-8244
  • Assigner
  • cret@cert.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2014-11-01T10:55:02
  • Last Modified Date
  • 2014-11-04T02:42:20
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:linksys:ea3500_firmware:*:*:*:*:*:*:*:* 1 OR 2.0.14294
cpe:2.3:h:linksys:ea3500:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:linksys:ea6700_firmware:*:153731:*:*:*:*:*:* 1 OR 1.1.40
cpe:2.3:h:linksys:ea6700:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:linksys:ea6500_firmware:*:153731:*:*:*:*:*:* 1 OR 1.1.40
cpe:2.3:h:linksys:ea6500:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:linksys:ea4500_firmware:*:*:*:*:*:*:*:* 1 OR 2.0.14212.1
cpe:2.3:h:linksys:ea4500:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:linksys:ea6900_firmware:*:158863:*:*:*:*:*:* 1 OR 1.1.42
cpe:2.3:h:linksys:ea6900:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:linksys:ea2700_firmware:*:*:*:*:*:*:*:* 1 OR 2.0.14294
cpe:2.3:h:linksys:ea2700:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:linksys:ea6400_firmware:*:153731:*:*:*:*:*:* 1 OR 1.1.40
cpe:2.3:h:linksys:ea6400:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:linksys:ea6200_firmware:*:153743:*:*:*:*:*:* 1 OR 1.1.41
cpe:2.3:h:linksys:ea6200:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:linksys:ea6300_firmware:*:153731:*:*:*:*:*:* 1 OR 1.1.40
cpe:2.3:h:linksys:ea6300:-:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:o:linksys:e4200v2_firmware:*:*:*:*:*:*:*:* 1 OR 2.0.14212.1
cpe:2.3:h:linksys:e4200v2:-:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 7.5
  • Severity
  • HIGH
  • Exploitability Score
  • 10
  • Impact Score
  • 6.4
References
Reference URL Reference Tags
http://www.kb.cert.org/vuls/id/447516 Exploit Patch Third Party Advisory US Government Resource
History
Created Old Value New Value Data Type Notes
2022-05-10 10:29:30 Added to TrackCVE
2022-12-02 02:08:20 cert@cert.org cret@cert.org CVE Assigner updated
2022-12-02 02:08:20 2014-11-01T10:55Z 2014-11-01T10:55:02 CVE Published Date updated
2022-12-02 02:08:20 2014-11-04T02:42:20 CVE Modified Date updated
2022-12-02 02:08:20 Analyzed Vulnerability Status updated