CVE-2014-9708
published 2015-03-31CVE-2014-9708: Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an…
PriorityP338medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
56.43%
98.9th percentile
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| embedthis | appweb | < 4.6.6 | 4.6.6 |
| embedthis | appweb | >= 5.0.0 < 5.2.1 | 5.2.1 |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| oracle | enterprise_communications_broker | <= 2.0.0 | — |
| paloalto | pan-os | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP requests containing a Range header with an empty/malformed value (e.g., 'Range: x=,') targeting Embedthis Appweb or PAN-OS web management interfaces — this triggers a NULL pointer dereference and causes a DoS. ↗
- →This is a pre-authenticated attack — no credentials are required. Monitor for the malformed Range header from unauthenticated sources against the web management interface. ↗
- ·Restrict web management interface access to a dedicated management network and limit source IPs to authorized hosts to reduce attack surface. ↗
- ·Affected PAN-OS versions span a wide range (5.0.x through 7.1.x); ensure detection/patching coverage includes all listed branches. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
Web interface denial of service
vendor_paloalto·2016-10-11·CVSS 5.0
CVE-2014-9708 [MEDIUM] Web interface denial of service
Web interface denial of service
Palo Alto Networks web management server is vulnerable to a denial-of-service attack. (Ref # PAN-64917/105311) (CVE-2014-9708)
This pre-authenticated denial-of-service attack could disrupt the web management interface.
This issue affects PAN-OS 5.0.19 and earlier; PAN-OS 5.1.12 and earlier; PAN-OS 6.0.14 and earlier; PAN-OS 6.1.14 and earlier; PAN-OS 7.0.10 and earlier; PAN-OS 7.1.5 and earlier
Affected products: PAN-OS
Solution: PAN-OS 5.0.20 and later; PAN-OS 5.1.13 and later; PAN-OS 6.0.15 and later; PAN-OS 6.1.15 and later; PAN-OS 7.0.11 and later; PAN-OS 7.1.6 and later
Workaround: Palo Alto Networks recommends to implement best practice by allowing web interface access only to a dedicated management network. Additionally, restrict the set of IP ad
GHSA
GHSA-3r9x-rvv2-cq7m: Embedthis Appweb before 4
ghsa_unreviewed·2022-05-14
CVE-2014-9708 [MEDIUM] CWE-476 GHSA-3r9x-rvv2-cq7m: Embedthis Appweb before 4
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/131157/Appweb-Web-Server-Denial-Of-Service.htmlhttp://seclists.org/fulldisclosure/2015/Apr/19http://seclists.org/fulldisclosure/2015/Mar/158http://www.openwall.com/lists/oss-security/2015/03/28/2http://www.openwall.com/lists/oss-security/2015/04/06/2http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/archive/1/535028/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/535028/100/1400/threadedhttp://www.securityfocus.com/bid/73407http://www.securitytracker.com/id/1037007https://github.com/embedthis/appweb/commit/7e6a925f5e86a19a7934a94bbd6959101d0b84eb#diff-7ca4d62c70220e0e226e7beac90c95d9L17348https://github.com/embedthis/appweb/issues/413https://security.paloaltonetworks.com/CVE-2014-9708https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved?language=en_UShttp://packetstormsecurity.com/files/131157/Appweb-Web-Server-Denial-Of-Service.htmlhttp://seclists.org/fulldisclosure/2015/Apr/19http://seclists.org/fulldisclosure/2015/Mar/158http://www.openwall.com/lists/oss-security/2015/03/28/2http://www.openwall.com/lists/oss-security/2015/04/06/2http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/archive/1/535028/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/535028/100/1400/threadedhttp://www.securityfocus.com/bid/73407http://www.securitytracker.com/id/1037007https://github.com/embedthis/appweb/commit/7e6a925f5e86a19a7934a94bbd6959101d0b84eb#diff-7ca4d62c70220e0e226e7beac90c95d9L17348https://github.com/embedthis/appweb/issues/413https://security.paloaltonetworks.com/CVE-2014-9708https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved?language=en_US
2015-03-31
Published