cbcvebase.
CVE-2014-9708
published 2015-03-31

CVE-2014-9708: Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an…

PriorityP338medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
56.43%
98.9th percentile
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".

Affected

20 ranges
VendorProductVersion rangeFixed in
embedthisappweb< 4.6.64.6.6
embedthisappweb>= 5.0.0 < 5.2.15.2.1
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
juniperjunos
oracleenterprise_communications_broker<= 2.0.0
paloaltopan-os

Detection & IOCsextracted from sources · hover to see the quote

otherRange: x=,
  • Detect HTTP requests containing a Range header with an empty/malformed value (e.g., 'Range: x=,') targeting Embedthis Appweb or PAN-OS web management interfaces — this triggers a NULL pointer dereference and causes a DoS.
  • This is a pre-authenticated attack — no credentials are required. Monitor for the malformed Range header from unauthenticated sources against the web management interface.
  • ·Restrict web management interface access to a dedicated management network and limit source IPs to authorized hosts to reduce attack surface.
  • ·Affected PAN-OS versions span a wide range (5.0.x through 7.1.x); ensure detection/patching coverage includes all listed branches.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.