PT-2002-2634 · Skystream · Skystream Emr5000
Published
2002-12-31
·
Updated
2023-12-28
·
CVE-2002-1912
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
SkyStream EMR5000 versions 1.16 through 1.18
Description
The issue allows remote attackers to cause a denial of service, resulting in a null pointer exception and kernel panic, by sending a large number of packets when the buffers are full. This occurs because the device does not drop packets or disable the Ethernet interface when the buffers are full.
Recommendations
For SkyStream EMR5000 versions 1.16 through 1.18, consider implementing traffic control measures to limit the number of incoming packets and prevent buffer overflow. As a temporary workaround, restrict access to the Ethernet interface to minimize the risk of exploitation.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Skystream Emr5000