ID

VAR-201310-0403


CVE

CVE-2013-6021


TITLE

Watchguard Extensible Threat Management (XTM) appliance version 11.7.4 contains a buffer overflow vulnerability

Trust: 0.8

sources: CERT/CC: VU#233990

DESCRIPTION

Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in a cookie. Watchguard Extensible Threat Management (XTM) Contains a stack buffer overflow vulnerability. Watchguard Extensible Threat Management (XTM) appliance is a next-generation network security appliance that includes firewalls, application control and intrusion prevention systems. The WGagent running on the XTM application has a security vulnerability in parsing the cookie sent to the WEB interface. Failed exploit attempts will result in a denial-of-service condition

Trust: 3.15

sources: NVD: CVE-2013-6021 // CERT/CC: VU#233990 // JVNDB: JVNDB-2013-004810 // CNVD: CNVD-2013-14028 // BID: 63227

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-14028

AFFECTED PRODUCTS

vendor:watchguardmodel:firewarescope:eqversion:11.3

Trust: 1.6

vendor:watchguardmodel:firewarescope:eqversion:11.7.2

Trust: 1.6

vendor:watchguardmodel:firewarescope:eqversion:11.4

Trust: 1.6

vendor:watchguardmodel:firewarescope:eqversion:11.0.2

Trust: 1.6

vendor:watchguardmodel:firewarescope:eqversion:11.6.6

Trust: 1.6

vendor:watchguardmodel:firewarescope:eqversion:11.3.6

Trust: 1.6

vendor:watchguardmodel:firewarescope:eqversion:11.5.3

Trust: 1.6

vendor:watchguardmodel:firewarescope:eqversion:11.5.1

Trust: 1.6

vendor:watchguardmodel:firewarescope:eqversion:11.4.2

Trust: 1.6

vendor:watchguardmodel:firewarescope:lteversion:11.7.4

Trust: 1.0

vendor:watchguardmodel:firewarescope:eqversion:11.2.3

Trust: 1.0

vendor:watchguardmodel:firewarescope:eqversion:11.1

Trust: 1.0

vendor:watchguardmodel: - scope: - version: -

Trust: 0.8

vendor:watchguardmodel:firewarescope:lteversion:version 11.7.4

Trust: 0.8

vendor:watchguardmodel:extensible threat management appliancescope:eqversion:11.7.4

Trust: 0.6

vendor:watchguardmodel:firewarescope:eqversion:11.7.4

Trust: 0.6

sources: CERT/CC: VU#233990 // CNVD: CNVD-2013-14028 // JVNDB: JVNDB-2013-004810 // CNNVD: CNNVD-201310-475 // NVD: CVE-2013-6021

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2013-6021
value: HIGH

Trust: 1.6

nvd@nist.gov: CVE-2013-6021
value: HIGH

Trust: 1.0

CNVD: CNVD-2013-14028
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201310-475
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2013-6021
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

NVD: CVE-2013-6021
severity: HIGH
baseScore: 9.3
vectorString: NONE
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2013-14028
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CERT/CC: VU#233990 // CNVD: CNVD-2013-14028 // JVNDB: JVNDB-2013-004810 // CNNVD: CNNVD-201310-475 // NVD: CVE-2013-6021

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.8

problemtype:CWE-121

Trust: 0.8

sources: CERT/CC: VU#233990 // JVNDB: JVNDB-2013-004810 // NVD: CVE-2013-6021

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201310-475

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201310-475

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-004810

EXPLOIT AVAILABILITY

sources: CERT/CC: VU#233990

PATCH

title:WatchGuard’s XTM 11.8 Software Fixes Buffer Overflow & XSS Vulnerabilitiesurl:http://watchguardsecuritycenter.com/2013/10/17/xtm-11-8-secfixes/

Trust: 0.8

title:WatchGuard Dimension and Fireware XTM 11.8url:http://watchguardsecuritycenter.com/2013/10/17/watchguard-dimension-and-fireware-xtm-11-8/

Trust: 0.8

title:Patch for the Watchguard Extensible Threat Management Stack Buffer Overflow Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/40485

Trust: 0.6

sources: CNVD: CNVD-2013-14028 // JVNDB: JVNDB-2013-004810

EXTERNAL IDS

db:CERT/CCid:VU#233990

Trust: 3.8

db:NVDid:CVE-2013-6021

Trust: 3.3

db:BIDid:63227

Trust: 1.9

db:EXPLOIT-DBid:29273

Trust: 1.0

db:OSVDBid:98752

Trust: 1.0

db:JVNid:JVNVU97653535

Trust: 0.8

db:JVNDBid:JVNDB-2013-004810

Trust: 0.8

db:CNVDid:CNVD-2013-14028

Trust: 0.6

db:CNNVDid:CNNVD-201310-475

Trust: 0.6

sources: CERT/CC: VU#233990 // CNVD: CNVD-2013-14028 // BID: 63227 // JVNDB: JVNDB-2013-004810 // CNNVD: CNNVD-201310-475 // NVD: CVE-2013-6021

REFERENCES

url:http://watchguardsecuritycenter.com/2013/10/17/xtm-11-8-secfixes/

Trust: 3.0

url:http://www.kb.cert.org/vuls/id/233990

Trust: 3.0

url:http://watchguardsecuritycenter.com/2013/10/17/watchguard-dimension-and-fireware-xtm-11-8/

Trust: 1.6

url:http://www.exploit-db.com/exploits/29273

Trust: 1.0

url:https://funoverip.net/2013/10/watchguard-cve-2013-6021-stack-based-buffer-overflow-exploit/

Trust: 1.0

url:http://www.securityfocus.com/bid/63227

Trust: 1.0

url:http://osvdb.org/98752

Trust: 1.0

url:http://cwe.mitre.org/data/definitions/121.html

Trust: 0.8

url:http://www.watchguard.com/products/xtm-main.asp

Trust: 0.8

url:http://www.watchguard.com/support/index.asp

Trust: 0.8

url:http://watchguardsecuritycenter.com/2013/10/17/watchguard-dimension-and-fireware

Trust: 0.8

url:-xtm-11-8/

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-6021

Trust: 0.8

url:http://jvn.jp/cert/jvnvu97653535/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-6021

Trust: 0.8

url:http://www.watchguard.com/

Trust: 0.3

sources: CERT/CC: VU#233990 // CNVD: CNVD-2013-14028 // BID: 63227 // JVNDB: JVNDB-2013-004810 // CNNVD: CNNVD-201310-475 // NVD: CVE-2013-6021

CREDITS

Jerome Nokin and Thierry Zoller of Verizon Enterprise Solutions.

Trust: 0.3

sources: BID: 63227

SOURCES

db:CERT/CCid:VU#233990
db:CNVDid:CNVD-2013-14028
db:BIDid:63227
db:JVNDBid:JVNDB-2013-004810
db:CNNVDid:CNNVD-201310-475
db:NVDid:CVE-2013-6021

LAST UPDATE DATE

2024-11-23T22:59:46.431000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#233990date:2013-10-18T00:00:00
db:CNVDid:CNVD-2013-14028date:2013-10-24T00:00:00
db:BIDid:63227date:2013-11-01T00:51:00
db:JVNDBid:JVNDB-2013-004810date:2013-10-22T00:00:00
db:CNNVDid:CNNVD-201310-475date:2013-10-21T00:00:00
db:NVDid:CVE-2013-6021date:2024-11-21T01:58:38.240

SOURCES RELEASE DATE

db:CERT/CCid:VU#233990date:2013-10-18T00:00:00
db:CNVDid:CNVD-2013-14028date:2013-10-24T00:00:00
db:BIDid:63227date:2013-10-18T00:00:00
db:JVNDBid:JVNDB-2013-004810date:2013-10-22T00:00:00
db:CNNVDid:CNNVD-201310-475date:2013-10-21T00:00:00
db:NVDid:CVE-2013-6021date:2013-10-19T10:36:08.573