ID

VAR-201310-0681


TITLE

Vu+ Solo Unauthorized Access Vulnerability

Trust: 0.9

sources: CNVD: CNVD-2013-13994 // BID: 63010

DESCRIPTION

Vu+SOLO does not perform any form of verification on the control software, allowing remote unauthenticated attackers to reboot the system. Vu + Solo is a VU + series high-definition satellite receiver using the Broadcom BCM7325 solution from Ceru of South Korea. An unauthorized access vulnerability exists in Vu + Solo. An attacker could use this vulnerability to gain access, perform malicious operations on the affected system, or cause a denial of service. This may results in a denial-of-service condition

Trust: 1.35

sources: CNVD: CNVD-2013-13994 // CNNVD: CNNVD-201310-266 // BID: 63010

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-13994

AFFECTED PRODUCTS

vendor:cerumodel:vu+ solo experimentalscope:eqversion:2011-08-22

Trust: 0.6

vendor:vumodel:soloscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2013-13994 // BID: 63010

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-13994
value: HIGH

Trust: 0.6

CNVD: CNVD-2013-13994
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2013-13994

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201310-266

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201310-266

EXTERNAL IDS

db:BIDid:63010

Trust: 1.5

db:CNVDid:CNVD-2013-13994

Trust: 0.6

db:CNNVDid:CNNVD-201310-266

Trust: 0.6

sources: CNVD: CNVD-2013-13994 // BID: 63010 // CNNVD: CNNVD-201310-266

REFERENCES

url:http://dariusfreamon.wordpress.com/2013/10/10/multiple-linux-tv-player-software-unauthenticatd-remote-dos/

Trust: 0.9

url:http://www.securityfocus.com/bid/63010

Trust: 0.6

url:http://vuplus.com/productsolo.html

Trust: 0.3

sources: CNVD: CNVD-2013-13994 // BID: 63010 // CNNVD: CNNVD-201310-266

CREDITS

Darius Freamon

Trust: 0.9

sources: BID: 63010 // CNNVD: CNNVD-201310-266

SOURCES

db:CNVDid:CNVD-2013-13994
db:BIDid:63010
db:CNNVDid:CNNVD-201310-266

LAST UPDATE DATE

2022-05-17T02:05:56.099000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-13994date:2013-10-24T00:00:00
db:BIDid:63010date:2013-10-10T00:00:00
db:CNNVDid:CNNVD-201310-266date:2013-10-17T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-13994date:2013-10-24T00:00:00
db:BIDid:63010date:2013-10-10T00:00:00
db:CNNVDid:CNNVD-201310-266date:2013-10-17T00:00:00