ID

VAR-200902-0626


CVE

CVE-2009-0680


TITLE

Netgear SSL312 of cgi-bin/welcome/VPN_only Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2009-004485

DESCRIPTION

cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted query string, as demonstrated using directory traversal sequences. NetGear SSL312 is prone to a remote denial-of-service vulnerability. Successfully exploiting this issue allows remote attackers to cause denial-of-service conditions. NetGear SSL312 is an SSL VPN product manufactured by Netgear that meets the remote access needs of small and medium-sized enterprises

Trust: 1.98

sources: NVD: CVE-2009-0680 // JVNDB: JVNDB-2009-004485 // BID: 33675 // VULHUB: VHN-38126

AFFECTED PRODUCTS

vendor:netgearmodel:ssl312scope:eqversion: -

Trust: 1.6

vendor:net gearmodel:ssl312scope: - version: -

Trust: 0.8

vendor:netgearmodel:ssl312scope:eqversion:0

Trust: 0.3

sources: BID: 33675 // JVNDB: JVNDB-2009-004485 // CNNVD: CNNVD-200902-499 // NVD: CVE-2009-0680

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-0680
value: HIGH

Trust: 1.0

NVD: CVE-2009-0680
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200902-499
value: HIGH

Trust: 0.6

VULHUB: VHN-38126
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2009-0680
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-38126
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-38126 // JVNDB: JVNDB-2009-004485 // CNNVD: CNNVD-200902-499 // NVD: CVE-2009-0680

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.9

sources: VULHUB: VHN-38126 // JVNDB: JVNDB-2009-004485 // NVD: CVE-2009-0680

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200902-499

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-200902-499

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-004485

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-38126

PATCH

title:Top Pageurl:http://www.netgear.com/

Trust: 0.8

sources: JVNDB: JVNDB-2009-004485

EXTERNAL IDS

db:NVDid:CVE-2009-0680

Trust: 2.5

db:BIDid:33675

Trust: 2.0

db:SECUNIAid:33896

Trust: 1.7

db:EXPLOIT-DBid:8008

Trust: 1.7

db:JVNDBid:JVNDB-2009-004485

Trust: 0.8

db:CNNVDid:CNNVD-200902-499

Trust: 0.7

db:MILW0RMid:8008

Trust: 0.6

db:XFid:312

Trust: 0.6

db:XFid:48605

Trust: 0.6

db:FULLDISCid:20090208 NETGEAR SSL312 ROUTER - REMOTE DOS

Trust: 0.6

db:VULHUBid:VHN-38126

Trust: 0.1

sources: VULHUB: VHN-38126 // BID: 33675 // JVNDB: JVNDB-2009-004485 // CNNVD: CNNVD-200902-499 // NVD: CVE-2009-0680

REFERENCES

url:http://www.helith.net/txt/netgear_ssl312_remote_dos.txt

Trust: 2.0

url:http://www.securityfocus.com/bid/33675

Trust: 1.7

url:http://archives.neohapsis.com/archives/fulldisclosure/2009-02/0084.html

Trust: 1.7

url:http://secunia.com/advisories/33896

Trust: 1.7

url:https://www.exploit-db.com/exploits/8008

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/48605

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-0680

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-0680

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/48605

Trust: 0.6

url:http://www.milw0rm.com/exploits/8008

Trust: 0.6

url:http://www.netgear.com/products/vpnandssl/sslvpnconcentrators/ssl312.aspx

Trust: 0.3

sources: VULHUB: VHN-38126 // BID: 33675 // JVNDB: JVNDB-2009-004485 // CNNVD: CNNVD-200902-499 // NVD: CVE-2009-0680

CREDITS

Rembrandt

Trust: 0.3

sources: BID: 33675

SOURCES

db:VULHUBid:VHN-38126
db:BIDid:33675
db:JVNDBid:JVNDB-2009-004485
db:CNNVDid:CNNVD-200902-499
db:NVDid:CVE-2009-0680

LAST UPDATE DATE

2025-04-10T23:24:13.096000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-38126date:2017-09-29T00:00:00
db:BIDid:33675date:2009-02-10T15:58:00
db:JVNDBid:JVNDB-2009-004485date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200902-499date:2009-02-23T00:00:00
db:NVDid:CVE-2009-0680date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-38126date:2009-02-22T00:00:00
db:BIDid:33675date:2009-02-06T00:00:00
db:JVNDBid:JVNDB-2009-004485date:2012-09-25T00:00:00
db:CNNVDid:CNNVD-200902-499date:2009-02-22T00:00:00
db:NVDid:CVE-2009-0680date:2009-02-22T22:30:01.047