CVE-2019-17006
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
Affected (13)
Products: Siemens: Ruggedcom Rox Mx5000 Firmware, Ruggedcom Rox Rx1400 Firmware, Ruggedcom Rox Rx1500 Firmware, Ruggedcom Rox Rx1501 Firmware, Ruggedcom Rox Rx1510 Firmware, Ruggedcom Rox Rx1511 Firmware, Ruggedcom Rox Rx1512 Firmware, Ruggedcom Rox Rx5000 Firmware · Mozilla: Network Security Services · Netapp: Hci Compute Node, Hci Management Node, Hci Storage Node, Solidfire
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Mx5000 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1400 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1500 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1501 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1510 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1511 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx1512 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.14.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ruggedcom Rox Rx5000 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.46 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions |
Related CWEs
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
References (10)
Source: security@mozilla.org
ExploitIssue TrackingPatchVendor Advisory
Source: security@mozilla.org
Third Party Advisory
Source: security@mozilla.org
Release NotesVendor Advisory
Source: security@mozilla.org
Third Party Advisory
Source: security@mozilla.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.