Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-9222

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2014-9222
Last Modified 23 Feb 2015 09:59:22
Published 24 Dec 2014 01:59:06
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2014-9222

Summary

AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.

Vulnerable Systems

Application

  • Allegrosoft Rompager 4.07


References

CONFIRM - http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-407666.htm

FULLDISC - 20141219 The Misfortune Cookie Vulnerability

MISC - http://mis.fortunecook.ie/

CERT-VN - VU#561444

CONFIRM - https://www.allegrosoft.com/allegro-software-urges-manufacturers-to-maintain-firmware-for-highest-level-of-embedded-device-security/news-press.html


Last Updated: 27 May 2016 11:07:54