Vulnerability Name: CVE-2017-11345 (CCN-128749) Assigned: 2017-07-14 Published: 2017-07-14 Updated: 2017-12-20 Summary: Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code on the router by hosting a crafted device description XML document (that includes a serviceType element) at a URL specified within a Location header in an SSDP response. CVSS v3 Severity: 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )6.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L )6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:U/RC:R )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-119 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2017-11345 Source: CCN Type: oss-sec Mailing List, Fri, 14 Jul 2017 11:23:56 +0800Re: Re: Asus wireless routers Global buffer overflow and Stack buffer overflow in networkmap Source: MISC Type: Mailing List, Third Party Advisoryhttp://www.openwall.com/lists/oss-security/2017/07/14/3 Source: CONFIRM Type: UNKNOWNhttps://asuswrt.lostrealm.ca/changelog Source: XF Type: UNKNOWNasus-cve201711345-bo(128749) Source: CCN Type: ASUS Web siteASUS devices Vulnerable Configuration: Configuration 1 :cpe:/o:asuswrt-merlin_project:rt-ac5300_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)AND cpe:/h:asuswrt-merlin_project:rt-ac5300:-:*:*:*:*:*:*:* Configuration 2 :cpe:/o:asuswrt-merlin_project:rt_ac1900p_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)AND cpe:/h:asuswrt-merlin_project:rt_ac1900p_:-:*:*:*:*:*:*:* Configuration 3 :cpe:/o:asuswrt-merlin_project:rt-ac68u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)AND cpe:/h:asuswrt-merlin_project:rt-ac68u:-:*:*:*:*:*:*:* Configuration 4 :cpe:/o:asuswrt-merlin_project:rt-ac68p_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)AND cpe:/h:asuswrt-merlin_project:rt-ac68p:-:*:*:*:*:*:*:* Configuration 5 :cpe:/o:asuswrt-merlin_project:rt-ac88u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)AND cpe:/h:asuswrt-merlin_project:rt-ac88u:-:*:*:*:*:*:*:* Configuration 6 :cpe:/o:asuswrt-merlin_project:rt-ac66u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)AND cpe:/h:asuswrt-merlin_project:rt-ac66u:-:*:*:*:*:*:*:* Configuration 7 :cpe:/o:asuswrt-merlin_project:rt-ac66u_b1_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)AND cpe:/h:asuswrt-merlin_project:rt-ac66u_b1:-:*:*:*:*:*:*:* Configuration 8 :cpe:/o:asuswrt-merlin_project:rt-ac58u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7485)AND cpe:/h:asuswrt-merlin_project:rt-ac58u:-:*:*:*:*:*:*:* Configuration 9 :cpe:/o:asuswrt-merlin_project:rt-ac56u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)AND cpe:/h:asuswrt-merlin_project:rt-ac56u:-:*:*:*:*:*:*:* Configuration 10 :cpe:/o:asuswrt-merlin_project:rt-ac55u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)AND cpe:/h:asuswrt-merlin_project:rt-ac55u:-:*:*:*:*:*:*:* Configuration 11 :cpe:/o:asuswrt-merlin_project:rt-ac52u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.4180)AND cpe:/h:asuswrt-merlin_project:rt-ac52u:-:*:*:*:*:*:*:* Configuration 12 :cpe:/o:asuswrt-merlin_project:rt-ac51u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)AND cpe:/h:asuswrt-merlin_project:rt-ac51u:-:*:*:*:*:*:*:* Configuration 13 :cpe:/o:asuswrt-merlin_project:rt-n18u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)AND cpe:/h:asuswrt-merlin_project:rt-n18u:-:*:*:*:*:*:*:* Configuration 14 :cpe:/o:asuswrt-merlin_project:rt-n66u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)AND cpe:/h:asuswrt-merlin_project:rt-n66u:-:*:*:*:*:*:*:* Configuration 15 :cpe:/o:asuswrt-merlin_project:rt-n56u_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.378.7177)AND cpe:/h:asuswrt-merlin_project:rt-n56u:-:*:*:*:*:*:*:* Configuration 16 :cpe:/o:asuswrt-merlin_project:rt-ac3200_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)AND cpe:/h:asuswrt-merlin_project:rt-ac3200:-:*:*:*:*:*:*:* Configuration 17 :cpe:/o:asuswrt-merlin_project:rt-ac3100_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7743)AND cpe:/h:asuswrt-merlin_project:rt-ac3100:-:*:*:*:*:*:*:* Configuration 18 :cpe:/o:asuswrt-merlin_project:rt_ac1200gu_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.5577)AND cpe:/h:asuswrt-merlin_project:rt_ac1200gu:-:*:*:*:*:*:*:* Configuration 19 :cpe:/o:asuswrt-merlin_project:rt_ac1200g_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.3167)AND cpe:/h:asuswrt-merlin_project:rt_ac1200g:-:*:*:*:*:*:*:* Configuration 20 :cpe:/o:asuswrt-merlin_project:rt-ac1200_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.9880)AND cpe:/h:asuswrt-merlin_project:rt-ac1200:-:*:*:*:*:*:*:* Configuration 21 :cpe:/o:asuswrt-merlin_project:rt-ac53_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.9883)AND cpe:/h:asuswrt-merlin_project:rt-ac53:-:*:*:*:*:*:*:* Configuration 22 :cpe:/o:asuswrt-merlin_project:rt-n12hp_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.2943)AND cpe:/h:asuswrt-merlin_project:rt-n12hp:-:*:*:*:*:*:*:* Configuration 23 :cpe:/o:asuswrt-merlin_project:rt-n12hp_b1_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.3479)AND cpe:/h:asuswrt-merlin_project:rt-n12hp_b1:-:*:*:*:*:*:*:* Configuration 24 :cpe:/o:asuswrt-merlin_project:rt-n12d1_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)AND cpe:/h:asuswrt-merlin_project:rt-n12d1:-:*:*:*:*:*:*:* Configuration 25 :cpe:/o:asuswrt-merlin_project:rt-n12+_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)AND cpe:/h:asuswrt-merlin_project:rt-n12+:-:*:*:*:*:*:*:* Configuration 26 :cpe:/o:asuswrt-merlin_project:rt_n12+_pro_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.9880)AND cpe:/h:asuswrt-merlin_project:rt_n12+_pro:-:*:*:*:*:*:*:* Configuration 27 :cpe:/o:asuswrt-merlin_project:rt-n16_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)AND cpe:/h:asuswrt-merlin_project:rt-n16:-:*:*:*:*:*:*:* Configuration 28 :cpe:/o:asuswrt-merlin_project:rt-n300_firmware:*:*:*:*:*:*:*:* (Version <= 3.0.0.4.380.7378)AND cpe:/h:asuswrt-merlin_project:rt-n300:-:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/h:asus:rt-n16:-:*:*:*:*:*:*:* OR cpe:/h:asus:rt-n12_d1:-:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
asuswrt-merlin_project rt-ac5300 firmware *
asuswrt-merlin_project rt-ac5300 -
asuswrt-merlin_project rt ac1900p firmware *
asuswrt-merlin_project rt ac1900p -
asuswrt-merlin_project rt-ac68u firmware *
asuswrt-merlin_project rt-ac68u -
asuswrt-merlin_project rt-ac68p firmware *
asuswrt-merlin_project rt-ac68p -
asuswrt-merlin_project rt-ac88u firmware *
asuswrt-merlin_project rt-ac88u -
asuswrt-merlin_project rt-ac66u firmware *
asuswrt-merlin_project rt-ac66u -
asuswrt-merlin_project rt-ac66u b1 firmware *
asuswrt-merlin_project rt-ac66u b1 -
asuswrt-merlin_project rt-ac58u firmware *
asuswrt-merlin_project rt-ac58u -
asuswrt-merlin_project rt-ac56u firmware *
asuswrt-merlin_project rt-ac56u -
asuswrt-merlin_project rt-ac55u firmware *
asuswrt-merlin_project rt-ac55u -
asuswrt-merlin_project rt-ac52u firmware *
asuswrt-merlin_project rt-ac52u -
asuswrt-merlin_project rt-ac51u firmware *
asuswrt-merlin_project rt-ac51u -
asuswrt-merlin_project rt-n18u firmware *
asuswrt-merlin_project rt-n18u -
asuswrt-merlin_project rt-n66u firmware *
asuswrt-merlin_project rt-n66u -
asuswrt-merlin_project rt-n56u firmware *
asuswrt-merlin_project rt-n56u -
asuswrt-merlin_project rt-ac3200 firmware *
asuswrt-merlin_project rt-ac3200 -
asuswrt-merlin_project rt-ac3100 firmware *
asuswrt-merlin_project rt-ac3100 -
asuswrt-merlin_project rt ac1200gu firmware *
asuswrt-merlin_project rt ac1200gu -
asuswrt-merlin_project rt ac1200g firmware *
asuswrt-merlin_project rt ac1200g -
asuswrt-merlin_project rt-ac1200 firmware *
asuswrt-merlin_project rt-ac1200 -
asuswrt-merlin_project rt-ac53 firmware *
asuswrt-merlin_project rt-ac53 -
asuswrt-merlin_project rt-n12hp firmware *
asuswrt-merlin_project rt-n12hp -
asuswrt-merlin_project rt-n12hp b1 firmware *
asuswrt-merlin_project rt-n12hp b1 -
asuswrt-merlin_project rt-n12d1 firmware *
asuswrt-merlin_project rt-n12d1 -
asuswrt-merlin_project rt-n12+ firmware *
asuswrt-merlin_project rt-n12+ -
asuswrt-merlin_project rt n12+ pro firmware *
asuswrt-merlin_project rt n12+ pro -
asuswrt-merlin_project rt-n16 firmware *
asuswrt-merlin_project rt-n16 -
asuswrt-merlin_project rt-n300 firmware *
asuswrt-merlin_project rt-n300 -
asus rt-n16 -
asus rt-n12 d1 -