Lucene search

K
cveRedhatCVE-2013-4216
HistoryAug 25, 2013 - 3:27 a.m.

CVE-2013-4216

2013-08-2503:27:32
CWE-264
redhat
web.nvd.nist.gov
19
cve
2013
4216
intel
wimax
network service
denial of service
data corruption
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.5

Confidence

High

EPSS

0

Percentile

5.1%

The Trace_OpenLogFile function in InfraStack/OSDependent/Linux/InfraStackModules/TraceModule/TraceModule.c in the Trace module in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices uses world-writable permissions for wimaxd.log, which allows local users to cause a denial of service (data corruption) by modifying this file.

Affected configurations

Nvd
Node
intelwimax_network_serviceRange1.5.2
OR
intelwimax_network_serviceMatch1.5.0
VendorProductVersionCPE
intelwimax_network_service*cpe:2.3:a:intel:wimax_network_service:*:*:*:*:*:*:*:*
intelwimax_network_service1.5.0cpe:2.3:a:intel:wimax_network_service:1.5.0:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.5

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2013-4216