[Japanese]
|
JVNDB-2016-000108
|
CG-WLBARAGM vulnerable to denial-of-service (DoS)
|
CG-WLBARAGM provided by Corega Inc is a wireless LAN router. CG-WLBARAGM contains a denial-of-service (DoS) vulnerability.
Yuji Ukai of FFRI, Inc reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 5.3 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
CVSS V2 Severity: Base Metrics 5.0 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Partial
|
|
Corega Inc
|
|
An unauthenticated remote attacker may cause the product to reboot.
|
[Apply a Workaround]
The following workarounds may mitigate the affects of this vulnerability.
* Disable the remote access function to avoid access to the product from the internet
* Encrypt wireless LAN communications to avoid access to the product from adjacent networks
Note that these workarounds above do not prevent access from local networks.
|
Corega Inc
|
- Improper Input Validation(CWE-20) [IPA Evaluation]
|
- CVE-2016-4823
|
- JVN : JVN#24409899
- National Vulnerability Database (NVD) : CVE-2016-4823
|
- [2016/06/22]
Web page was published
[2016/06/29]
References : Content was added
|