ID

VAR-201305-0368


TITLE

SAProuter NI Routing Message Handling Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2013-05969

DESCRIPTION

SAProuter is an SAP program that protects your SAP network from unauthorized access behavior. A remote attacker can execute arbitrary code or cause a heap-based buffer overflow by sending a specially crafted NI mail route, possibly executing arbitrary code

Trust: 0.72

sources: CNVD: CNVD-2013-05969 // IVD: f6e5c1e2-1f22-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: f6e5c1e2-1f22-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-05969

AFFECTED PRODUCTS

vendor:sapmodel:saprouter (basis sp 0/kernel patchscope:eqversion:7.3072072068)

Trust: 0.6

vendor:sapmodel: - scope:eqversion:*

Trust: 0.2

vendor:saproutermodel:(basis sp 0/kernel patchscope:eqversion:7.3072072068)

Trust: 0.2

sources: IVD: f6e5c1e2-1f22-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-05969

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-05969
value: HIGH

Trust: 0.6

IVD: f6e5c1e2-1f22-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

CNVD: CNVD-2013-05969
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: f6e5c1e2-1f22-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: f6e5c1e2-1f22-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-05969

TYPE

Permission permission and access control

Trust: 0.2

sources: IVD: f6e5c1e2-1f22-11e6-abef-000c29c66e3d

PATCH

title:SAProuter NI Routing Message Handling Vulnerability Patchurl:https://www.cnvd.org.cn/patchinfo/show/34241

Trust: 0.6

sources: CNVD: CNVD-2013-05969

EXTERNAL IDS

db:CNVDid:CNVD-2013-05969

Trust: 0.8

db:SECUNIAid:53436

Trust: 0.6

db:IVDid:F6E5C1E2-1F22-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: f6e5c1e2-1f22-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-05969

REFERENCES

url:http://secunia.com/advisories/53436/

Trust: 0.6

sources: CNVD: CNVD-2013-05969

SOURCES

db:IVDid:f6e5c1e2-1f22-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2013-05969

LAST UPDATE DATE

2022-05-17T02:00:04.162000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-05969date:2013-05-28T00:00:00

SOURCES RELEASE DATE

db:IVDid:f6e5c1e2-1f22-11e6-abef-000c29c66e3ddate:2013-05-23T00:00:00
db:CNVDid:CNVD-2013-05969date:2013-05-23T00:00:00