CVE-2014-3427: CRLF Injection
Published Jul 16, 2014
·Updated
CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet.
Affected Software
1 affected component
Yealink Voip Phone Firmware=28.72.0.2
Event History
Jul 16, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3427?
CVE-2014-3427 is considered to be of medium severity due to its potential for HTTP response splitting attacks.
2
How do I fix CVE-2014-3427?
To fix CVE-2014-3427, update to a firmware version that is not affected by this vulnerability.
3
What systems are affected by CVE-2014-3427?
CVE-2014-3427 affects Yealink VoIP Phones running firmware version 28.72.0.2.
4
What type of attack can be carried out using CVE-2014-3427?
CVE-2014-3427 allows remote attackers to conduct HTTP response splitting attacks through CRLF injection.
5
Is CVE-2014-3427 remotely exploitable?
Yes, CVE-2014-3427 can be exploited remotely due to its nature as a network protocol vulnerability.