Denial of service through specially crafted RTSP packet

Advisory ID CVE Number Date discovered Severity Advisory revision
STORM-2019-028 12/06/2019 low v1

Vulnerability details

A Denial-of-Service can occur when RTSP interleaved traffic is processed by an SNS firewall.

Impacted products

ProductsSeverityDetail
Stormshield Network Security low SNS is impacted

Revisions

Version Date Description
v1 Initial release


Stormshield Network Security

CVSS v2 Overall Score: 1.4      

Analysis

Impacted version

A Denial-of-Service can occur when a specially crafted RTSP packet is processed by an SNS firewall.

  • Every version greater or equal than 2.7

Workaround solution

Solution

If the firewall operates in a context where RTSP protocol is not used, ensure that interleaving mode is forbidden (CONFIGURATION-> Protocols -> VoIP/Streaming -> RTSP-> “Allow interleaving”).

Default configuration does not allow interleaving therefore a firewall using the default configuration is not impacted.

The vulnerability will be fixed by the following versions:

  • SNS 3.7.10
  • SNS 3.10.1
  • SNS 4.0.1


Access vector Access complexity Authentication Confidentiality impact Integrity impact Availability impact
Network Medium None None None Complete
CVSS Base score: 7.1 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C)
Exploitability Remediation Level Report Confidence
Proof of concept code Official fix Confirmed
CVSS Temporal score: 5.6 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C/E:POC/RL:OF/RC:C)
Collateral Damage Potential Target Distribution
None Low [0-25%]
CVSS Environmental score: 1.4 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C/E:POC/RL:OF/RC:C/CDP:N/TD:L/CR:ND/IR:ND/AR:ND)