7.5

CVE-2002-1912

Exploit
SkyStream EMR5000 1.16 through 1.18 does not drop packets or disable the Ethernet interface when the buffers are full, which allows remote attackers to cause a denial of service (null pointer exception and kernel panic) via a large number of packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SkystreamEmr5000 Version1.16
SkystreamEmr5000 Version1.17
SkystreamEmr5000 Version1.18
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.3% 0.869
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

http://www.globalintersec.com/adv/skystream-2002021001.txt
Patch
Exploit
Broken Link
http://www.iss.net/security_center/static/10380.php
Broken Link
http://www.securityfocus.com/archive/1/295516
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/5977
Third Party Advisory
Broken Link
VDB Entry