PT-2016-5780 · Meinberg · Meinberg Lantime M300+10
B0Yd
+1
·
Publicado
2016-07-03
·
Atualizado
2017-09-03
·
CVE-2016-3962
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Meinberg IMS-LANTIME M3000 versions prior to 6.20.004
Meinberg IMS-LANTIME M1000 versions prior to 6.20.004
Meinberg IMS-LANTIME M500 versions prior to 6.20.004
Meinberg LANTIME M900 versions prior to 6.20.004
Meinberg LANTIME M600 versions prior to 6.20.004
Meinberg LANTIME M400 versions prior to 6.20.004
Meinberg LANTIME M300 versions prior to 6.20.004
Meinberg LANTIME M200 versions prior to 6.20.004
Meinberg LANTIME M100 versions prior to 6.20.004
Meinberg SyncFire 1100 versions prior to 6.20.004
Meinberg LCES versions prior to 6.20.004
Description
A stack-based buffer overflow issue exists in the NTP time-server interface, allowing remote attackers to obtain sensitive information, modify data, or cause a denial of service via a crafted parameter in a POST request to a vulnerable API endpoint.
Recommendations
Update the firmware of Meinberg IMS-LANTIME M3000 to version 6.20.004 or later.
Update the firmware of Meinberg IMS-LANTIME M1000 to version 6.20.004 or later.
Update the firmware of Meinberg IMS-LANTIME M500 to version 6.20.004 or later.
Update the firmware of Meinberg LANTIME M900 to version 6.20.004 or later.
Update the firmware of Meinberg LANTIME M600 to version 6.20.004 or later.
Update the firmware of Meinberg LANTIME M400 to version 6.20.004 or later.
Update the firmware of Meinberg LANTIME M300 to version 6.20.004 or later.
Update the firmware of Meinberg LANTIME M200 to version 6.20.004 or later.
Update the firmware of Meinberg LANTIME M100 to version 6.20.004 or later.
Update the firmware of Meinberg SyncFire 1100 to version 6.20.004 or later.
Update the firmware of Meinberg LCES to version 6.20.004 or later.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Meinberg Ims-Lantime M1000
Meinberg Ims-Lantime M3000
Meinberg Ims-Lantime M500
Meinberg Lantime M100
Meinberg Lantime M200
Meinberg Lantime M300
Meinberg Lantime M400
Meinberg Lantime M600
Meinberg Lantime M900
Meinberg Lces
Meinberg Syncfire 1100