CVE-2014-7249 - CVE House
Back to Database
Status published Critical CVE-2014-7249

Buffer overflow on the Allied Telesis AR440S, AR441S, AR442S, AR745,...

Vulnerability Description

Buffer overflow on the Allied Telesis AR440S, AR441S, AR442S, AR745, AR750S, AR750S-DP, AT-8624POE, AT-8624T/2M, AT-8648T/2SP, AT-8748XL, AT-8848, AT-9816GB, AT-9924T, AT-9924Ts, CentreCOM AR415S, CentreCOM AR450S, CentreCOM AR550S, CentreCOM AR570S, CentreCOM 8700SL, CentreCOM 8948XL, CentreCOM 9924SP, CentreCOM 9924T/4SP, Rapier 48i, and SwitchBlade4000 with firmware before 2.9.1-21 allows remote attackers to execute arbitrary code via a crafted HTTP POST request.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-7249

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

alliedtelesis

View all reports →

Affected Software

centrecom ar415s firmware, centrecom ar415s, at-8624t\/2m firmware, at-8624t\/2m, ar442s firmware, ar442s, at-9924t firmware, at-9924t, at-8848 firmware, at-8848, rapier 48i firmware, rapier 48i, centrecom ar450s firmware, centrecom ar450s, ar745 firmware, ar745, ar441s firmware, ar441s, centrecom 9924sp firmware, centrecom 9924sp, switchblade4000 firmware, switchblade4000, at-8624poe firmware, at-8624poe, centrecom 9924t\/4sp firmware, centrecom 9924t\/4sp, at-9816gb firmware, at-9816gb, at-9924ts firmware, at-9924ts, ar750s firmware, ar750s, centrecom ar570s firmware, centrecom ar570s, centrecom 8948xl firmware, centrecom 8948xl, at-8648t\/2sp firmware, at-8648t\/2sp, centrecom 8700sl firmware, centrecom ar8700sl, ar750s-dp firmware, ar750s-dp, centrecom ar550s firmware, centrecom ar550s, at-8748xl firmware, at-8748xl, ar440s firmware, ar440s
Vulnerable Versions:
0

Timeline

Official Publish: December 19th, 2014
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.