Vulnerability Name:

CVE-2014-0997 (CCN-100393)

Assigned:2014-01-07
Published:2015-01-26
Updated:2018-10-09
Summary:WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android 4.1.2 as used in the Motorola RAZR HD, and potentially other unspecified Android releases before 5.0.1 and 5.0.2 does not properly handle exceptions, which allows remote attackers to cause a denial of service (reboot) via a crafted 802.11 probe response frame.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
3.3 Low (CCN CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P)
2.7 Low (CCN Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-19
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2014-0997

Source: MISC
Type: Exploit, Issue Tracking, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/130107/Android-WiFi-Direct-Denial-Of-Service.html

Source: CCN
Type: Full Disclosure Mailing List, Mon, 26 Jan 2015 13:27:20 -0300
Android WiFi-Direct Denial of Service

Source: FULLDISC
Type: Exploit, Issue Tracking, Mailing List, Third Party Advisory
20150126 [CORE-2015-0002] - Android WiFi-Direct Denial of Service

Source: CCN
Type: Nexus – Google Web site
Nexus – Google

Source: CCN
Type: LG Web site
LG G2 - D806 - Aprendiendo de vos | LG Argentina

Source: CCN
Type: Motorola Web site
Droid Razr M

Source: CCN
Type: Samsung Web site
Specs - Wi-Fi Tabs SM-T310 | Samsung Galaxy Tab

Source: BUGTRAQ
Type: UNKNOWN
20150126 [CORE-2015-0002] - Android WiFi-Direct Denial of Service

Source: BID
Type: Third Party Advisory, VDB Entry
72311

Source: CCN
Type: BID-72311
Multiple Android Devices CVE-2014-0997 Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
android-wifidirect-cve20140997-dos(100393)

Source: CCN
Type: Packet Storm Security [01-26-2015]
Android WiFi-Direct Denial Of Service

Source: MISC
Type: Exploit, Issue Tracking, Third Party Advisory
https://www.coresecurity.com/advisories/android-wifi-direct-denial-service

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [01-26-2015]

Source: EXPLOIT-DB
Type: Exploit, Issue Tracking, Third Party Advisory, VDB Entry
35913

Vulnerable Configuration:Configuration 1:
  • cpe:/o:google:android:4.4.4:*:*:*:*:*:*:*
  • AND
  • cpe:/h:google:nexus_4:-:*:*:*:*:*:*:*
  • OR cpe:/h:google:nexus_5:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:google:android:4.2.2:*:*:*:*:*:*:*
  • AND
  • cpe:/h:lg:d806:-:*:*:*:*:*:*:*
  • OR cpe:/h:samsung:sm-t310:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:google:android:4.1.2:*:*:*:*:*:*:*
  • AND
  • cpe:/h:motorola:razr_hd:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    google android 4.4.4
    google nexus 4 -
    google nexus 5 -
    google android 4.2.2
    lg d806 -
    samsung sm-t310 -
    google android 4.1.2
    motorola razr hd -