ID

VAR-201006-0501


TITLE

Motorola SB5101 Haxorware Firmware Denial of Service Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2010-1078

DESCRIPTION

The Motorola SB5101 is a cable modem. Motorola SB5101 Hax0rware has multiple security vulnerabilities that allow remote attackers to perform denial of service attacks on devices. - Unverified attackers can send multiple log reset requests to the eventlog.cgi script to restart the device and cause a denial of service attack. - The unauthenticated attacker sends a GET request with more than 1 byte but no correct request line to the device 80 port, such as [ GET /somepath/file.cgi ], the http daemon crashes. Motorola SB5101 Haxorware Firmware is prone to multiple denial-of-service vulnerabilities. An attacker can exploit these issues to cause the application to crash, resulting in a denial-of-service condition. Haxorware 1.1 R30, 1.1 R32 and 1.1 R39 are vulnerable; other versions may also be affected

Trust: 0.81

sources: CNVD: CNVD-2010-1078 // BID: 40635

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2010-1078

AFFECTED PRODUCTS

vendor:nomodel: - scope: - version: -

Trust: 0.6

vendor:surfboardmodel:hacker haxorware r39scope:eqversion:1.1

Trust: 0.3

vendor:surfboardmodel:hacker haxorware r32scope:eqversion:1.1

Trust: 0.3

vendor:surfboardmodel:hacker haxorware r30scope:eqversion:1.1

Trust: 0.3

sources: CNVD: CNVD-2010-1078 // BID: 40635

THREAT TYPE

network

Trust: 0.3

sources: BID: 40635

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 40635

EXTERNAL IDS

db:BIDid:40635

Trust: 0.9

db:CNVDid:CNVD-2010-1078

Trust: 0.6

sources: CNVD: CNVD-2010-1078 // BID: 40635

REFERENCES

url:http://www.securityfocus.com/bid/40635

Trust: 0.6

url:http://www.sbhacker.net/forum/

Trust: 0.3

sources: CNVD: CNVD-2010-1078 // BID: 40635

CREDITS

Dillon Beresford

Trust: 0.3

sources: BID: 40635

SOURCES

db:CNVDid:CNVD-2010-1078
db:BIDid:40635

LAST UPDATE DATE

2022-05-17T01:41:43.371000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-1078date:2010-06-09T00:00:00
db:BIDid:40635date:2010-06-08T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2010-1078date:2010-06-09T00:00:00
db:BIDid:40635date:2010-06-08T00:00:00