Lucene search

K
cveMitreCVE-2006-3687
HistoryJul 21, 2006 - 2:03 p.m.

CVE-2006-3687

2006-07-2114:03:00
mitre
web.nvd.nist.gov
41
cve-2006-3687
universal plug and play
upnp
buffer overflow
d-link
di-524
di-604
di-624
di-784
wbr-1310
wbr-2310
ebr-2310
remote code execution
network security

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.1

Confidence

High

EPSS

0.361

Percentile

97.2%

Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in D-Link DI-524, DI-604 Broadband Router, DI-624, D-Link DI-784, WBR-1310 Wireless G Router, WBR-2310 RangeBooster G Router, and EBR-2310 Ethernet Broadband Router allows remote attackers to execute arbitrary code via a long M-SEARCH request to UDP port 1900.

Affected configurations

Nvd
Node
d-linkdi-604_broadband_router
OR
d-linkdi-784
OR
d-linkebr-2310_ethernet_broadband_router
OR
d-linkwbr-1310_wireless_g_router
OR
d-linkwbr-2310_rangebooster_g_router
OR
dlinkdi-524
OR
dlinkdi-624
VendorProductVersionCPE
d-linkdi-604_broadband_router*cpe:2.3:h:d-link:di-604_broadband_router:*:*:*:*:*:*:*:*
d-linkdi-784*cpe:2.3:h:d-link:di-784:*:*:*:*:*:*:*:*
d-linkebr-2310_ethernet_broadband_router*cpe:2.3:h:d-link:ebr-2310_ethernet_broadband_router:*:*:*:*:*:*:*:*
d-linkwbr-1310_wireless_g_router*cpe:2.3:h:d-link:wbr-1310_wireless_g_router:*:*:*:*:*:*:*:*
d-linkwbr-2310_rangebooster_g_router*cpe:2.3:h:d-link:wbr-2310_rangebooster_g_router:*:*:*:*:*:*:*:*
dlinkdi-524*cpe:2.3:h:dlink:di-524:*:*:*:*:*:*:*:*
dlinkdi-624*cpe:2.3:h:dlink:di-624:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.1

Confidence

High

EPSS

0.361

Percentile

97.2%

Related for CVE-2006-3687