7.8

CVE-2013-5209

The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does not properly initialize the state-cookie data structure, which allows remote attackers to obtain sensitive information from kernel stack memory by reading packet data in INIT-ACK chunks.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FreebsdFreebsd Version8.3
FreebsdFreebsd Version9.0
FreebsdFreebsd Version9.1
FreebsdFreebsd Version9.1 Updatep4
FreebsdFreebsd Version9.1 Updatep5
FreebsdFreebsd Version9.2 Updateprerelease
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.677
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:C/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.