Lucene search

K
jvnJapan Vulnerability NotesJVN:20671901
HistoryMar 18, 2013 - 12:00 a.m.

JVN#20671901: VxWorks SSH server (IPSSH) denial-of-service (DoS) vulnerability

2013-03-1800:00:00
Japan Vulnerability Notes
jvn.jp
31

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.065 Low

EPSS

Percentile

93.8%

The SSH server (IPSSH) implementation in VxWorks contains a denial-of-service (DoS) vulnerability due to an issue in the processing authentication requests.

Impact

Recieiving a specially crafted packet for a public key authentication request may cause the server to hang and SSH access to be unavailable until the next reboot. In addition, arbitrary code may be executed on the server.

Solution

Apply a patch
Apply the appropriate patch according to the information provided by the developer.

Products Affected

  • VxWorks versions 6.5 through 6.9

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.065 Low

EPSS

Percentile

93.8%

Related for JVN:20671901