Lucene search

K
cveMitreCVE-2008-5421
HistoryDec 11, 2008 - 3:30 p.m.

CVE-2008-5421

2008-12-1115:30:00
CWE-399
mitre
web.nvd.nist.gov
35
netwin smsgate
ssl
denial of service
cve-2008-5421
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.7

Confidence

High

EPSS

0.007

Percentile

80.8%

The SSL web administration service in NetWin SmsGate 1.1n and earlier allows remote attackers to cause a denial of service (hang) via (1) a large integer in the Content-Length HTTP header; (2) an invalid value in the Content-Length HTTP header, as demonstrated by a negative integer; or (3) a missing Content-Length HTTP header.

Affected configurations

Nvd
Node
netwinsmsgateRange1.1n
OR
netwinsmsgateMatch1.0a
OR
netwinsmsgateMatch1.0c
OR
netwinsmsgateMatch1.0h
OR
netwinsmsgateMatch1.0r
OR
netwinsmsgateMatch1.0w
OR
netwinsmsgateMatch1.1m
VendorProductVersionCPE
netwinsmsgate*cpe:2.3:a:netwin:smsgate:*:*:*:*:*:*:*:*
netwinsmsgate1.0acpe:2.3:a:netwin:smsgate:1.0a:*:*:*:*:*:*:*
netwinsmsgate1.0ccpe:2.3:a:netwin:smsgate:1.0c:*:*:*:*:*:*:*
netwinsmsgate1.0hcpe:2.3:a:netwin:smsgate:1.0h:*:*:*:*:*:*:*
netwinsmsgate1.0rcpe:2.3:a:netwin:smsgate:1.0r:*:*:*:*:*:*:*
netwinsmsgate1.0wcpe:2.3:a:netwin:smsgate:1.0w:*:*:*:*:*:*:*
netwinsmsgate1.1mcpe:2.3:a:netwin:smsgate:1.1m:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.7

Confidence

High

EPSS

0.007

Percentile

80.8%

Related for CVE-2008-5421