CVE-2018-5391
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered and fixed over the years. The current vulnerability (CVE-2018-5391) became exploitable in the Linux kernel with the increase of the IP fragment reassembly queue size.
Affected (130)
Products: Linux: Linux Kernel · Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation · Debian: Debian Linux · +4 more
Show all products
Linux: Linux Kernel · Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation · Debian: Debian Linux · Canonical: Ubuntu Linux · Microsoft: Windows 10, Windows 7, Windows 8.1, Windows Rt 8.1, Windows Server 2008, Windows Server 2012, Windows Server 2016 · F5: Big Ip Access Policy Manager, Big Ip Advanced Firewall Manager, Big Ip Analytics, Big Ip Application Acceleration Manager, Big Ip Application Security Manager, Big Ip Domain Name System, Big Ip Edge Gateway, Big Ip Fraud Protection Service, Big Ip Global Traffic Manager, Big Ip Link Controller, Big Ip Local Traffic Manager, Big Ip Policy Enforcement Manager, Big Ip Webaccelerator · Siemens: Ruggedcom Rm1224 Firmware, Ruggedcom Rox Ii Firmware, Scalance M 800 Firmware, Scalance S615 Firmware, Scalance Sc 600 Firmware, Scalance W1700 Ieee 802.11ac Firmware, Scalance W700 Ieee 802.11a/b/g/n Firmware, Simatic Net Cp 1242 7 Firmware, Simatic Net Cp 1243 1 Firmware, Simatic Net Cp 1243 7 Lte Eu Firmware, Simatic Net Cp 1243 7 Lte Us Firmware, Simatic Net Cp 1243 8 Irc Firmware, Simatic Net Cp 1542sp 1 Firmware, Simatic Net Cp 1542sp 1 Irc Firmware, Simatic Net Cp 1543 1 Firmware, Simatic Net Cp 1543sp 1 Firmware, Simatic Rf185c Firmware, Simatic Rf186c Firmware, Simatic Rf186ci Firmware, Simatic Rf188 Firmware, Simatic Rf188ci Firmware, Sinema Remote Connect Server Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.9 to 4.18 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 | |
| Version 6.0 | |
| Version 6.4 | |
| Version 6.7 | |
| Version 6.6 | |
| Version 6.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.04 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 | |
| From 11.5.1 to 11.6.5.1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rm1224 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.13.3 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Ii | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance M 800 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance S615 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Sc 600 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance W1700 Ieee 802.11ac | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance W700 Ieee 802.11a/b/g/n | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1242 7 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1243 1 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1243 7 Lte Eu | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1243 7 Lte Us | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1243 8 Irc | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1542sp 1 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1542sp 1 Irc | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1543 1 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1543sp 1 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.3 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Rf185c | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.3 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Rf186c | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.3 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Rf186ci | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.3 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Rf188 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.3 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Rf188ci | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.1 to 2.0.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinema Remote Connect Server | All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-400
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
References (70)
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Broken Link
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
PatchVendor Advisory
Source: cret@cert.org
Mailing ListMitigationThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.