Vulnerability Name: | CVE-2009-2189 (CCN-64163) | ||||||||
Assigned: | 2009-06-24 | ||||||||
Published: | 2010-12-16 | ||||||||
Updated: | 2011-01-19 | ||||||||
Summary: | The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 does not limit the rate of (1) Router Advertisement and (2) Neighbor Discovery packets, which allows remote attackers to cause a denial of service (resource consumption and device restart) by sending many packets. | ||||||||
CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 6.1 Medium (CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C) 4.5 Medium (Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
2.4 Low (CCN Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-399 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-2189 Source: APPLE Type: Patch, Vendor Advisory APPLE-SA-2010-12-16-1 Source: CCN Type: SA42665 Apple AirPort / Time Capsule Multiple Vulnerabilities Source: CCN Type: SECTRACK ID: 1024907 Apple Time Capsule and AirPort Base Station Bugs Let Remote Users Deny Service or Access Ostensibly Protected Hosts Source: CCN Type: Apple Web site About the security content of Time Capsule and AirPort Base Station (802.11n) Firmware 7.5.2 Source: CONFIRM Type: Patch, Vendor Advisory http://support.apple.com/kb/HT4298 Source: CCN Type: OSVDB ID: 70149 Apple AirPort Multiple Products ICMPv6 Router Advertisement / Neighbor Discovery Packet Saturation Remote DoS Source: CCN Type: BID-45490 Apple Time Capsule and AirPort Base Station (CVE-2009-2189) Remote Denial of Service Vulnerability Source: SECTRACK Type: UNKNOWN 1024907 Source: XF Type: UNKNOWN airport-ipv6-dos(64163) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |