ID

VAR-200312-0446


CVE

CVE-2003-1497


TITLE

Linksys BEFSX41 EtherFast Router Log View Remote Denial of Service Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2003-3132 // CNNVD: CNNVD-200312-245

DESCRIPTION

Buffer overflow in the system log viewer of Linksys BEFSX41 1.44.3 allows remote attackers to cause a denial of service via an HTTP request with a long Log_Page_Num variable. Linksys BEFSX41 is a broadband router that includes a web-based management interface.  Linksys BEFSX41 lacks sufficient filtering when processing user-submitted input. Remote attackers can use this vulnerability to conduct denial-of-service attacks on routers.  Linksys BEFSX41 general default address (http://192.168.1.1) contains a WEB-based management interface, which can be accessed using "get" mode. Due to lack of sufficient filtering of the "Log_Page_Num" parameter, when a long string is sent to the system log Viewer "Log_Page_Num" parameter can cause router to crash. Linksys BEFSX41 EtherFast Routers are prone to a denial of service. This issue is exposed via the log viewer in the web administrative interface. By submitting an invalid value for the "Log_Page_Num" parameter, it is possible to trigger this condition, causing the router to be unresponsive. While exploitation does require a logged in administrative user to submit a request to the log viewer with malformed parameters, it is possible that the admin could be tricked into visiting a specially crafted URI that contains the IP address of the router and malformed URI parameters

Trust: 1.8

sources: NVD: CVE-2003-1497 // CNVD: CNVD-2003-3132 // BID: 8834 // VULHUB: VHN-8322

AFFECTED PRODUCTS

vendor:linksysmodel:befsx41scope:eqversion:1.43.3

Trust: 1.6

vendor:nonemodel: - scope: - version: -

Trust: 0.6

vendor:linksysmodel:befsx41scope:eqversion:1.44.3

Trust: 0.3

vendor:linksysmodel:befsx41scope:neversion:1.45.3

Trust: 0.3

sources: CNVD: CNVD-2003-3132 // BID: 8834 // CNNVD: CNNVD-200312-245 // NVD: CVE-2003-1497

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2003-1497
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200312-245
value: MEDIUM

Trust: 0.6

VULHUB: VHN-8322
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2003-1497
severity: MEDIUM
baseScore: 6.3
vectorString: AV:N/AC:M/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.8
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-8322
severity: MEDIUM
baseScore: 6.3
vectorString: AV:N/AC:M/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.8
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-8322 // CNNVD: CNNVD-200312-245 // NVD: CVE-2003-1497

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.1

sources: VULHUB: VHN-8322 // NVD: CVE-2003-1497

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200312-245

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-200312-245

EXTERNAL IDS

db:NVDid:CVE-2003-1497

Trust: 2.3

db:BIDid:8834

Trust: 2.0

db:SREASONid:3298

Trust: 1.7

db:CNNVDid:CNNVD-200312-245

Trust: 0.7

db:CNVDid:CNVD-2003-3132

Trust: 0.6

db:XFid:13436

Trust: 0.6

db:NSFOCUSid:5555

Trust: 0.6

db:BUGTRAQid:20031015 LINKSYS ETHERFAST ROUTER DENIAL OF SERVICE ATTACK

Trust: 0.6

db:VULHUBid:VHN-8322

Trust: 0.1

sources: CNVD: CNVD-2003-3132 // VULHUB: VHN-8322 // BID: 8834 // CNNVD: CNNVD-200312-245 // NVD: CVE-2003-1497

REFERENCES

url:http://www.securityfocus.com/bid/8834

Trust: 1.7

url:http://www.securityfocus.com/archive/1/341309

Trust: 1.7

url:http://www.linksys.com/download/vertxt/befsx41_1453.txt

Trust: 1.7

url:http://securityreason.com/securityalert/3298

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/13436

Trust: 1.1

url:http://xforce.iss.net/xforce/xfdb/13436

Trust: 0.6

url:http://www.nsfocus.net/vulndb/5555

Trust: 0.6

url:/archive/1/341309

Trust: 0.3

sources: VULHUB: VHN-8322 // BID: 8834 // CNNVD: CNNVD-200312-245 // NVD: CVE-2003-1497

CREDITS

DigitalPranksters※ krazysnake@digitalpranksters.com

Trust: 0.6

sources: CNNVD: CNNVD-200312-245

SOURCES

db:CNVDid:CNVD-2003-3132
db:VULHUBid:VHN-8322
db:BIDid:8834
db:CNNVDid:CNNVD-200312-245
db:NVDid:CVE-2003-1497

LAST UPDATE DATE

2024-08-14T14:16:12.008000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2003-3132date:2003-10-15T00:00:00
db:VULHUBid:VHN-8322date:2017-07-29T00:00:00
db:BIDid:8834date:2003-10-15T00:00:00
db:CNNVDid:CNNVD-200312-245date:2003-12-31T00:00:00
db:NVDid:CVE-2003-1497date:2017-07-29T01:29:14.467

SOURCES RELEASE DATE

db:CNVDid:CNVD-2003-3132date:2003-10-15T00:00:00
db:VULHUBid:VHN-8322date:2003-12-31T00:00:00
db:BIDid:8834date:2003-10-15T00:00:00
db:CNNVDid:CNNVD-200312-245date:2003-10-15T00:00:00
db:NVDid:CVE-2003-1497date:2003-12-31T05:00:00