PT-2008-2738 · NetGear+1 · Netgear Wn802T+1

Julien Tinnes

+1

·

Publicado

2008-09-05

·

Atualizado

2018-10-11

·

CVE-2008-1144

CVSS v2.0

6.3

Média

VetorAV:N/AC:M/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Marvell driver for the Netgear WN802T Wi-Fi access point version 1.3.16
Description The issue concerns the Marvell driver's improper parsing of EAPoL-Key packets, which can be exploited by remote authenticated users. This can lead to a denial of service, causing the device to reboot or hang, or potentially allow the execution of arbitrary code. The exploitation involves sending a malformed EAPoL-Key packet with a crafted advertised length.
Recommendations For version 1.3.16, consider disabling the handling of EAPoL-Key packets as a temporary workaround until a patch is available. Restrict access to the network to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1144

Produtos afetados

Marvell Driver
Netgear Wn802T