Vulnerability Name: | CVE-2019-6474 (CCN-166131) | ||||||||||||||||
Assigned: | 2019-08-28 | ||||||||||||||||
Published: | 2019-08-28 | ||||||||||||||||
Updated: | 2020-08-24 | ||||||||||||||||
Summary: | A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are rejected as invalid when the server tries to load leases from storage on restart. If the number of such leases exceeds a hard-coded limit in the Kea code, a server trying to restart will conclude that there is a problem with its lease store and give up. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2 | ||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.0 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 6.1 Medium (CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:C)
| ||||||||||||||||
Vulnerability Type: | CWE-772 | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-6474 Source: XF Type: UNKNOWN isc-kea-cve20196474-dos(166131) Source: CCN Type: ISC Web site CVE-2019-6474: An oversight when validating incoming client requests can lead to a situation where the Kea server will exit when trying to restart Source: CONFIRM Type: Vendor Advisory https://kb.isc.org/docs/cve-2019-6474 Source: CCN Type: oss-sec Mailing List, Wed, 28 Aug 2019 23:46:31 -0800 Three vulnerabilities in Kea DHCP disclosed by ISC, 28 August 2019 Source: CCN Type: WhiteSource Vulnerability Database CVE-2019-6474 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |