Kernel panic due to MLDv2 packet

Advisory ID CVE Number Date discovered Severity Advisory revision
STORM-2019-008 CVE-2019-5608 08/08/2019 medium v1

Vulnerability details

An ICMPv6 packet that encapsulate an MLDv2 header can potentially panic the kernel.

Impacted products

ProductsSeverityDetail
Netasq medium MLDv2 packets is handled by Netasq UTMs.

Revisions

Version Date Description
v1  08/08/2019 Initial release

 



Netasq

CVSS v2 Overall Score: 6.6      

Analysis

Impacted version

Netasq UTMs 9.x are vulnerable to this CVE.

  • Netasq 9.X

Workaround solution

Solution

There is no workaround solution.

No solution



Access vector Access complexity Authentication Confidentiality impact Integrity impact Availability impact
Network Low None None None Complete
CVSS Base score: 7.8 CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Remediation Level Report Confidence
Unproven that exploit exists Unavailable Confirmed
CVSS Temporal score: 6.6 CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:U/RC:C)
Collateral Damage Potential Target Distribution
None High [76-100%]
CVSS Environmental score: 6.6 CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:U/RC:C/CDP:N/TD:H/CR:ND/IR:ND/AR:ND)