Vulnerability Name: | CVE-2014-2718 (CCN-98316) | ||||||||
Assigned: | 2014-10-28 | ||||||||
Published: | 2014-10-28 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:C/A:N) 5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:C/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-345 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-2718 Source: MISC Type: Exploit http://dnlongen.blogspot.com/2014/10/CVE-2014-2718-Asus-RT-MITM.html Source: MISC Type: Exploit http://packetstormsecurity.com/files/128904/ASUS-Router-Man-In-The-Middle.html Source: CCN Type: Full Disclosure Mailing List, Tue, 28 Oct 2014 11:29:48 -0500 CVE-2014-2718: ASUS wireless router updates are vulnerable to a MITM attack Source: FULLDISC Type: Exploit 20141028 CVE-2014-2718: ASUS wireless router updates are vulnerable to a MITM attack Source: CCN Type: ASUS Web site RT routers Source: BID Type: UNKNOWN 70791 Source: CCN Type: BID-70791 ASUS RT Series Wireless Routers CVE-2014-2718 Man in the Middle Security Bypass Vulnerability Source: XF Type: UNKNOWN asus-cve20142718-mitm(98316) Source: XF Type: UNKNOWN asus-cve20142718-mitm(98316) Source: CONFIRM Type: UNKNOWN https://support.t-mobile.com/docs/DOC-21994 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |