PT-2009-6650 · Ralink Technology · Rt2570+4

Aviv

·

Published

1970-01-01

·

Updated

2018-10-30

·

CVE-2009-0282

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions rt2400 versions 1.2.2 beta3 and earlier rt2500-source (affected versions not specified) rt2570-source (affected versions not specified) Ralink Technology USB wireless adapter (RT73) version 3.08
Description The issue concerns multiple vulnerabilities in wireless adapter drivers, including rt2400, rt2500, rt2570, and rt61, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely. An integer overflow in the Ralink Technology USB wireless adapter (RT73) driver allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Probe Request packet with a long SSID.
Recommendations For rt2400 versions 1.2.2 beta3 and earlier, update to a version later than 1.2.2 beta3. For rt2500-source, restrict access to vulnerable modules to minimize the risk of exploitation until a patch is available. For rt2570-source, avoid using vulnerable parameters in affected API endpoints until the issue is resolved. For Ralink Technology USB wireless adapter (RT73) version 3.08, consider disabling the vulnerable function until a patch is available. At the moment, there is no information about a newer version that contains a fix for rt2500-source and rt2570-source.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01422
BDU:2015-01423
BDU:2015-01939
BDU:2015-02665
BDU:2015-02666
BDU:2015-09378
CVE-2009-0282
DSA-1712-1
DSA-1713-1
DSA-1714-1

Affected Products

Rt73
Rt2400
Rt2500
Rt2570
Rt61