ID

VAR-200304-0140


TITLE

Buffalo WBRG54 Wireless Broadband Router Remote Denial of Service Attack Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2003-0984

DESCRIPTION

The Buffalo WBRG54 is a router for wireless broadband. Buffalo WBRG54 has problems handling super-multiple ICMP packets, which can be exploited by remote attackers to perform denial of service attacks on devices. According to the vulnerability finder's test, it uses two broadband routers WBR-g54 (the first one is: g54-01, the second is g54-02), and both connections are peer-to-peer mode connections: [atacker PC ]--[g54-01]-.-.-per-to-pear-.-.-[g54-02]--[victim PC] If you use a lot of ICMP packets (ping -f <victim IP can be used in Linux) >) Submitted to the device, which can cause the connection to be broken. A vulnerability has been reported for the WBRG54 device that may result in a denial of service. The vulnerability occurs when a vulnerable device receives numerous ICMP packets. In some cases, this will result in the device behaving unpredictably and denying service

Trust: 0.81

sources: CNVD: CNVD-2003-0984 // BID: 7282

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2003-0984

AFFECTED PRODUCTS

vendor:buffalomodel:technology wireless broadband router wbrg54scope:eqversion:1.11

Trust: 0.9

vendor:buffalomodel:technology wireless broadband router wbrg54scope:eqversion:1.13

Trust: 0.9

sources: CNVD: CNVD-2003-0984 // BID: 7282

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2003-0984
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2003-0984
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2003-0984

THREAT TYPE

network

Trust: 0.3

sources: BID: 7282

TYPE

Failure to Handle Exceptional Conditions

Trust: 0.3

sources: BID: 7282

EXTERNAL IDS

db:BIDid:7282

Trust: 0.9

db:CNVDid:CNVD-2003-0984

Trust: 0.6

sources: CNVD: CNVD-2003-0984 // BID: 7282

REFERENCES

url:http://marc.theaimsgroup.com/?l=bugtraq&m=104948240828389&w=2

Trust: 0.6

url:http://www.buffalotech.com/

Trust: 0.3

url:/archive/1/317480

Trust: 0.3

sources: CNVD: CNVD-2003-0984 // BID: 7282

CREDITS

Discovery of this vulnerability credited to Pavel shpac <shpac@ru.ru>.

Trust: 0.3

sources: BID: 7282

SOURCES

db:CNVDid:CNVD-2003-0984
db:BIDid:7282

LAST UPDATE DATE

2022-05-17T02:05:38.387000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2003-0984date:2014-01-20T00:00:00
db:BIDid:7282date:2003-04-04T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2003-0984date:2003-04-04T00:00:00
db:BIDid:7282date:2003-04-04T00:00:00