ID

VAR-201708-0235


CVE

CVE-2014-8872


TITLE

AVM FRITZ!Box 6810 LTE and 6840 LTE Code injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2014-008371

DESCRIPTION

Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50. AVM FRITZ!Box 6810 LTE and 6840 LTE Contains a code injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. AVMFRITZ! Box6810LTE and FRITZ! Box6840 LTE are router products of the German AVM company. A code injection vulnerability exists in AVMFRITZ!Box6810LTE and FRITZ!Box6840LTE due to a program failing to properly verify the cryptographic signature. A remote attacker can exploit this vulnerability to inject and execute malicious code. There is a code injection vulnerability in AVM FRITZ!Box 6810 LTE and FRITZ!Box 6840 LTE

Trust: 2.25

sources: NVD: CVE-2014-8872 // JVNDB: JVNDB-2014-008371 // CNVD: CNVD-2017-30661 // VULHUB: VHN-76817

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-30661

AFFECTED PRODUCTS

vendor:avmmodel:fritz\!box 6840 ltescope:eqversion: -

Trust: 1.6

vendor:avmmodel:fritz\!box 6810 ltescope:eqversion: -

Trust: 1.6

vendor:avmmodel:fritz!box 6810 ltescope: - version: -

Trust: 0.8

vendor:avmmodel:fritz!box 6840 ltescope: - version: -

Trust: 0.8

vendor:avmmodel:fritz!boxscope:eqversion:7490

Trust: 0.6

vendor:avmmodel:fritz!boxscope:eqversion:7390

Trust: 0.6

vendor:avmmodel:fritz!boxscope:eqversion:7270v3

Trust: 0.6

sources: CNVD: CNVD-2017-30661 // JVNDB: JVNDB-2014-008371 // CNNVD: CNNVD-201708-1385 // NVD: CVE-2014-8872

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-8872
value: HIGH

Trust: 1.0

NVD: CVE-2014-8872
value: HIGH

Trust: 0.8

CNVD: CNVD-2017-30661
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201708-1385
value: CRITICAL

Trust: 0.6

VULHUB: VHN-76817
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-8872
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-30661
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-76817
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2014-8872
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-30661 // VULHUB: VHN-76817 // JVNDB: JVNDB-2014-008371 // CNNVD: CNNVD-201708-1385 // NVD: CVE-2014-8872

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.9

sources: VULHUB: VHN-76817 // JVNDB: JVNDB-2014-008371 // NVD: CVE-2014-8872

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201708-1385

TYPE

code injection

Trust: 0.6

sources: CNNVD: CNNVD-201708-1385

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-008371

PATCH

title:FRITZ!Box 6840 LTE Serviceurl:https://avm.de/service/fritzbox/fritzbox-6840-lte/uebersicht/

Trust: 0.8

title:FRITZ!Box 6810 LTE Serviceurl:https://avm.de/service/fritzbox/fritzbox-6810-lte/uebersicht/

Trust: 0.8

title:Patch for AVMFRITZ!Box6810LTE and FRITZ!Box6840LTE code injection vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/104086

Trust: 0.6

title:AVM FRITZ!Box 6810 LTE and FRITZ!Box 6840 LTE Fixes for code injection vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=75159

Trust: 0.6

sources: CNVD: CNVD-2017-30661 // JVNDB: JVNDB-2014-008371 // CNNVD: CNNVD-201708-1385

EXTERNAL IDS

db:NVDid:CVE-2014-8872

Trust: 3.1

db:PACKETSTORMid:130040

Trust: 2.5

db:JVNDBid:JVNDB-2014-008371

Trust: 0.8

db:CNNVDid:CNNVD-201708-1385

Trust: 0.7

db:CNVDid:CNVD-2017-30661

Trust: 0.6

db:VULHUBid:VHN-76817

Trust: 0.1

sources: CNVD: CNVD-2017-30661 // VULHUB: VHN-76817 // JVNDB: JVNDB-2014-008371 // CNNVD: CNNVD-201708-1385 // NVD: CVE-2014-8872

REFERENCES

url:http://packetstormsecurity.com/files/130040/avm-fritz-box-firmware-signature-bypass.html

Trust: 2.5

url:http://seclists.org/fulldisclosure/2015/jan/86

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2014-8872

Trust: 1.4

url:http://www.securityfocus.com/archive/1/534522/100/0/threaded

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-8872

Trust: 0.8

url:http://www.securityfocus.com/archive/1/archive/1/534522/100/0/threaded

Trust: 0.6

sources: CNVD: CNVD-2017-30661 // VULHUB: VHN-76817 // JVNDB: JVNDB-2014-008371 // CNNVD: CNNVD-201708-1385 // NVD: CVE-2014-8872

SOURCES

db:CNVDid:CNVD-2017-30661
db:VULHUBid:VHN-76817
db:JVNDBid:JVNDB-2014-008371
db:CNNVDid:CNNVD-201708-1385
db:NVDid:CVE-2014-8872

LAST UPDATE DATE

2025-04-20T23:34:19.505000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-30661date:2017-10-19T00:00:00
db:VULHUBid:VHN-76817date:2018-10-09T00:00:00
db:JVNDBid:JVNDB-2014-008371date:2017-10-02T00:00:00
db:CNNVDid:CNNVD-201708-1385date:2017-10-09T00:00:00
db:NVDid:CVE-2014-8872date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-30661date:2017-10-19T00:00:00
db:VULHUBid:VHN-76817date:2017-08-29T00:00:00
db:JVNDBid:JVNDB-2014-008371date:2017-10-02T00:00:00
db:CNNVDid:CNNVD-201708-1385date:2017-08-28T00:00:00
db:NVDid:CVE-2014-8872date:2017-08-29T01:35:12.390