Tech Analysis research archive
Tech Analysis finds remote code execution vulnerability in Cisco cable modems and gateways, CVE-2014-3306
Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.
What was reported
On 16 July 2014 Cisco published an advisory for a buffer overflow in the web server of several of its wireless residential gateway and cable modem products, assigned CVE-2014-3306. In Cisco's words, the flaw could allow an unauthenticated, remote attacker to exploit a buffer overflow and cause arbitrary code execution. Nine models running software based on BFC 5.5.2 or older were affected: the DPC3212, DPC3825, EPC3212, EPC3825, DPC3010, DPC3925, DPQ3925, EPC3010 and EPC3925. Cisco gave it the maximum CVSS v2 base score of 10.0 and stated that the vulnerability was reported to Cisco by Chris Watts of Tech Analysis.
Tech Analysis announced the finding on this page on 21 July 2014, quoting the Cisco advisory identifier ciscosa-20140716-cm, Cisco bug CSCup40808, AusCERT bulletin ESB-2014.1179 and the NVD record. The discovery was reported that week by SecurityWeek and Threatpost, each naming Chris Watts of Tech Analysis; the original Tech Analysis news index also recorded coverage by The Hacker News, The Register and Computer Business Review.
Primary sources
- Cisco: Cisco Wireless Residential Gateway Remote Code Execution Vulnerability (first published 16 July 2014)
- CVE-2014-3306 on cve.org
- Archived copy of the original Tech Analysis article (Internet Archive)
- Threatpost, 17 July 2014: Cisco Patches Wireless Residential Gateway Vulnerabilities
- SecurityWeek, 17 July 2014: Cisco Patches Serious Vulnerability Affecting Modems, Wireless Gateways
Attribution
Cisco's advisory states: "This vulnerability was reported to Cisco by Chris Watts of Tech Analysis." Contemporary reporting by Threatpost and SecurityWeek repeats the attribution.
See the full research index for all public vulnerability records credited to Chris Watts.