| Vulnerability Name: | CVE-2009-0680 (CCN-48605) | ||||||||
| Assigned: | 2009-02-08 | ||||||||
| Published: | 2009-02-08 | ||||||||
| Updated: | 2017-09-29 | ||||||||
| Summary: | cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted query string, as demonstrated using directory traversal sequences. | ||||||||
| CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L)
| ||||||||
| CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:H/RL:U/RC:UR)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:H/RL:U/RC:UR)
| ||||||||
| Vulnerability Type: | CWE-22 | ||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||
| References: | Source: CCN Type: Full-Disclosure Mailing List, Sun Feb 08 2009 - 17:51:03 CST Netgear SSL312 Router - remote DoS Source: FULLDISC Type: UNKNOWN 20090208 Netgear SSL312 Router - remote DoS Source: MITRE Type: CNA CVE-2009-0680 Source: CCN Type: SA33896 Netgear SSL312 Web Interface Denial of Service Vulnerability Source: SECUNIA Type: Vendor Advisory 33896 Source: MISC Type: Exploit http://www.helith.net/txt/netgear_ssl312_remote_dos.txt Source: CCN Type: NETGEAR Web site NETGEAR SSL312 - ProSafe SSL VPN Concentrator 25 Source: CCN Type: OSVDB ID: 51847 NETGEAR SSL312 Web Interface cgi-bin/welcome/VPN_only Crafted Request Remote DoS Source: BID Type: Exploit 33675 Source: CCN Type: BID-33675 NetGear SSL312 CGI Binary Remote Denial of Service Vulnerability Source: XF Type: UNKNOWN netgear-ssl312-dos(48605) Source: XF Type: UNKNOWN netgear-ssl312-dos(48605) Source: EXPLOIT-DB Type: UNKNOWN 8008 | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||