7.5

CVE-2019-17596

Exploit

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

Data is provided by the National Vulnerability Database (NVD)
GolangGo Version >= 1.12 < 1.12.11
GolangGo Version >= 1.13 < 1.13.2
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
FedoraprojectFedora Version30
FedoraprojectFedora Version31
RedhatDeveloper Tools Version1.0
RedhatEnterprise Linux Version8.0
OpensuseLeap Version15.0
OpensuseLeap Version15.1
AristaCloudvision Portal Version >= 2018.1.0 <= 2018.2.3
AristaCloudvision Portal Version2019.1.0
AristaCloudvision Portal Version2019.1.1
AristaCloudvision Portal Version2019.1.2
AristaTerminattr Version <= 1.7.2
AristaEos Version <= 4.23.1f
AristaMos Version <= 0.25
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.34% 0.842
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-436 Interpretation Conflict

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.