[Japanese]
|
JVNDB-2014-000123
|
GIGAPOD vulnerable to denial-of-service (DoS)
|
GIGAPOD provided by TripodWorks CO.,LTD. contains a denial-of-service (DoS) vulnerability.
GIGAPOD file servers (Appliance model and Software model) from TripodWorks CO.,LTD. provide two web interfaces. First, a user web interface via ports 80/443, and a second, an administrative web interface via port 8001. The administrative web interface uses a version of the Apache HTTP server which contains a flaw in handling HTTP requests (CVE-2011-3192). As a result, GIGAPOD contains a denial-of-service (DoS) vulnerability.
Teruo Yamada of IOS Corporation reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 7.8 (High) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Complete
|
|
TripodWorks CO.,LTD
- GIGAPOD 2010 / GIGAPOD 3 Appliance model versions 3.01.02 and earlier
- GIGAPOD 2010 / GIGAPOD 3 Software model versions 3.01.02 and earlier
- GIGAPOD OFFICEHARD Appliance model versions 3.04.03 and earlier
|
|
A remote attacker may be able to cause a denial-of-service (DoS).
|
[Update the software]
Apply the appropriate update according to the information provided by the developer.
|
TripodWorks CO.,LTD
|
- Resource Management Errors(CWE-399) [IPA Evaluation]
|
- CVE-2014-5329
|
- JVN : JVN#23809730
- National Vulnerability Database (NVD) : CVE-2014-5329
|
- [2014/10/16]
Web page was published
- [2024/05/13]
References : Content was added
|