ID

VAR-200903-0547


CVE

CVE-2009-1152


TITLE

Siemens Gigaset SE461 WiMAX Router Remote Denial of Service Vulnerability

Trust: 0.8

sources: IVD: 6b80e5b0-23cc-11e6-abef-000c29c66e3d // CNNVD: CNNVD-200903-476

DESCRIPTION

Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a denial of service (device restart and loss of configuration) by connecting to TCP port 53, then closing the connection. Gigaset SE461 WiMAX router is prone to a denial-of-service vulnerability because it fails to adequately handle malformed requests. Successful exploits will deny service to legitimate users. Gigaset SE461 is a high-speed wireless router from Siemens. The WEB management interface of the Gigaset SE461 router does not correctly verify the request submitted by the user. An attacker could trigger the vulnerability by connecting directly to the device or using specially crafted web content

Trust: 2.16

sources: NVD: CVE-2009-1152 // JVNDB: JVNDB-2009-005922 // BID: 34220 // IVD: 6b80e5b0-23cc-11e6-abef-000c29c66e3d // VULHUB: VHN-38598

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 6b80e5b0-23cc-11e6-abef-000c29c66e3d

AFFECTED PRODUCTS

vendor:siemensmodel:gigaset se461 wimax routerscope:eqversion:1.5-bl024.9.6401

Trust: 2.4

vendor:siemensmodel:gigaset se461 wimax router 1.5-bl024.9.6401scope: - version: -

Trust: 0.3

vendor:gigaset se461 wimax routermodel:1.5-bl024.9.6401scope: - version: -

Trust: 0.2

sources: IVD: 6b80e5b0-23cc-11e6-abef-000c29c66e3d // BID: 34220 // JVNDB: JVNDB-2009-005922 // CNNVD: CNNVD-200903-476 // NVD: CVE-2009-1152

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-1152
value: HIGH

Trust: 1.0

NVD: CVE-2009-1152
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200903-476
value: HIGH

Trust: 0.6

IVD: 6b80e5b0-23cc-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

VULHUB: VHN-38598
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2009-1152
severity: HIGH
baseScore: 7.3
vectorString: AV:A/AC:M/AU:N/C:N/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

IVD: 6b80e5b0-23cc-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.3
vectorString: AV:A/AC:M/AU:N/C:N/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-38598
severity: HIGH
baseScore: 7.3
vectorString: AV:A/AC:M/AU:N/C:N/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: IVD: 6b80e5b0-23cc-11e6-abef-000c29c66e3d // VULHUB: VHN-38598 // JVNDB: JVNDB-2009-005922 // CNNVD: CNNVD-200903-476 // NVD: CVE-2009-1152

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2009-1152

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-200903-476

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-200903-476

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-005922

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-38598

PATCH

title:Top Pageurl:http://gigaset.com/

Trust: 0.8

sources: JVNDB: JVNDB-2009-005922

EXTERNAL IDS

db:NVDid:CVE-2009-1152

Trust: 2.7

db:BIDid:34220

Trust: 2.0

db:EXPLOIT-DBid:8260

Trust: 1.7

db:CNNVDid:CNNVD-200903-476

Trust: 0.9

db:JVNDBid:JVNDB-2009-005922

Trust: 0.8

db:XFid:49365

Trust: 0.6

db:XFid:461

Trust: 0.6

db:MILW0RMid:8260

Trust: 0.6

db:IVDid:6B80E5B0-23CC-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:VULHUBid:VHN-38598

Trust: 0.1

sources: IVD: 6b80e5b0-23cc-11e6-abef-000c29c66e3d // VULHUB: VHN-38598 // BID: 34220 // JVNDB: JVNDB-2009-005922 // CNNVD: CNNVD-200903-476 // NVD: CVE-2009-1152

REFERENCES

url:http://www.securityfocus.com/bid/34220

Trust: 1.7

url:http://helith.net/txt/siemens_gigaset_se461_wimax_router_remote_dos.txt

Trust: 1.7

url:https://www.exploit-db.com/exploits/8260

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/49365

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-1152

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-1152

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/49365

Trust: 0.6

url:http://www.milw0rm.com/exploits/8260

Trust: 0.6

url:http://gigaset.com/shc/0,1935,hq_en_0_122770_rarnrnrnrn,00.html

Trust: 0.3

sources: VULHUB: VHN-38598 // BID: 34220 // JVNDB: JVNDB-2009-005922 // CNNVD: CNNVD-200903-476 // NVD: CVE-2009-1152

CREDITS

Benkei

Trust: 0.9

sources: BID: 34220 // CNNVD: CNNVD-200903-476

SOURCES

db:IVDid:6b80e5b0-23cc-11e6-abef-000c29c66e3d
db:VULHUBid:VHN-38598
db:BIDid:34220
db:JVNDBid:JVNDB-2009-005922
db:CNNVDid:CNNVD-200903-476
db:NVDid:CVE-2009-1152

LAST UPDATE DATE

2025-04-10T23:03:12.350000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-38598date:2017-09-29T00:00:00
db:BIDid:34220date:2009-03-24T12:46:00
db:JVNDBid:JVNDB-2009-005922date:2012-12-20T00:00:00
db:CNNVDid:CNNVD-200903-476date:2009-03-26T00:00:00
db:NVDid:CVE-2009-1152date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:IVDid:6b80e5b0-23cc-11e6-abef-000c29c66e3ddate:2009-03-26T00:00:00
db:VULHUBid:VHN-38598date:2009-03-26T00:00:00
db:BIDid:34220date:2009-03-23T00:00:00
db:JVNDBid:JVNDB-2009-005922date:2012-12-20T00:00:00
db:CNNVDid:CNNVD-200903-476date:2009-03-26T00:00:00
db:NVDid:CVE-2009-1152date:2009-03-26T14:30:00.280