PT-2010-1562 · Addonics · Addonics Nas Adapter Nasu2Fw41

H00Die

·

Published

2010-03-29

·

Updated

2018-10-10

·

CVE-2009-4753

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Addonics NAS Adapter NASU2FW41 with loader 1.17
Description The issue is related to multiple buffer overflows in the FTP server, which can be exploited by remote attackers to cause a denial of service, specifically a TCP/IP outage. This can be achieved by sending long arguments to certain commands, including the XRMD, delete, RNFR, or RNTO command.
Recommendations For Addonics NAS Adapter NASU2FW41 with loader 1.17, consider restricting access to the FTP server until a fix is available. As a temporary workaround, limit the length of arguments that can be passed to the XRMD, delete, RNFR, or RNTO commands to prevent buffer overflows. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4753

Affected Products

Addonics Nas Adapter Nasu2Fw41