CVE-2014-3648 - CVE House
Back to Database
Status published High CVE-2014-3648

The simplepush server iterates through the application installations and pushes...

Vulnerability Description

The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless exceptions when those endpoints can't be reached or can slow the server down by purposefully wasting it's time with slow endpoints. Similarly, one can provide whatever HTTP end point they want. This turns the server into a DDOS vector or an anonymizer for the posting of malware and so on.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-3648

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Jboss Aerogear
Vulnerable Versions:
Jboss Aerogear 1.0.0.final

Timeline

Official Publish: July 1st, 2022
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)