ID

VAR-201311-0197


CVE

CVE-2013-5997


TITLE

D-Link DES-3800 Series vulnerable to denial-of-service (DoS)

Trust: 0.8

sources: JVNDB: JVNDB-2013-000109

DESCRIPTION

Unspecified vulnerability in the SSH implementation on D-Link Japan DES-3800 devices with firmware before R4.50B58 allows remote authenticated users to cause a denial of service (device hang) via unknown vectors, a different vulnerability than CVE-2013-5998. DES-3800 Series provided by D-Link Japan contains a denial-of-service (DoS) vulnerability due to an issue in the implementation of SSH. Note that this vulnerability is different from JVN#28812735. Hisashi Kojima, Masahiro Nakada of Fujitsu Laboratories Ltd. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.A user who can login using SSH may cause the product to stop responding. The D-Link DES-3800 is a three-layer 100M network managed switch. D-Link DES-3800 Series are prone to a denial-of-service vulnerability. An attacker can exploit this issue to cause the device to stop responding, denying service to legitimate users

Trust: 2.52

sources: NVD: CVE-2013-5997 // JVNDB: JVNDB-2013-000109 // CNVD: CNVD-2013-14707 // BID: 63871 // VULHUB: VHN-65999

IOT TAXONOMY

category:['IoT', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-14707

AFFECTED PRODUCTS

vendor:dlinkmodel:des-3800scope:eqversion:4.50

Trust: 1.6

vendor:dlinkmodel:des-3800scope:eqversion:4.00

Trust: 1.6

vendor:dlinkmodel:des-3800scope:eqversion:*

Trust: 1.0

vendor:d linkmodel:des-3800scope:eqversion:series firmware prior to r4.50b58

Trust: 0.8

vendor:d linkmodel:des-3800scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2013-14707 // JVNDB: JVNDB-2013-000109 // CNNVD: CNNVD-201311-362 // NVD: CVE-2013-5997

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-5997
value: MEDIUM

Trust: 1.0

IPA: JVNDB-2013-000109
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2013-14707
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201311-362
value: MEDIUM

Trust: 0.6

VULHUB: VHN-65999
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-5997
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

IPA: JVNDB-2013-000109
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2013-14707
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-65999
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2013-14707 // VULHUB: VHN-65999 // JVNDB: JVNDB-2013-000109 // CNNVD: CNNVD-201311-362 // NVD: CVE-2013-5997

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2013-5997

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201311-362

TYPE

Design Error

Trust: 0.3

sources: BID: 63871

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-000109

PATCH

title:DES-3800 Series - DES-3828url:http://www.dlink-jp.com/product/des-3828

Trust: 0.8

title:DES-3800 Series - DES-3828Purl:http://www.dlink-jp.com/product/des-3828p

Trust: 0.8

title:DES-3800 Series - DES-3828DCurl:http://www.dlink-jp.com/product/des-3828dc

Trust: 0.8

title:DES-3800 Series - DES-3852url:http://www.dlink-jp.com/product/des-3852

Trust: 0.8

title:D-Link DES-3800 Series SSH Patch for Remote Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/41317

Trust: 0.6

sources: CNVD: CNVD-2013-14707 // JVNDB: JVNDB-2013-000109

EXTERNAL IDS

db:NVDid:CVE-2013-5997

Trust: 3.4

db:JVNid:JVN65312543

Trust: 3.1

db:JVNDBid:JVNDB-2013-000109

Trust: 3.1

db:BIDid:63871

Trust: 1.0

db:CNNVDid:CNNVD-201311-362

Trust: 0.7

db:CNVDid:CNVD-2013-14707

Trust: 0.6

db:JVNid:JVN#65312543

Trust: 0.6

db:VULHUBid:VHN-65999

Trust: 0.1

sources: CNVD: CNVD-2013-14707 // VULHUB: VHN-65999 // BID: 63871 // JVNDB: JVNDB-2013-000109 // CNNVD: CNNVD-201311-362 // NVD: CVE-2013-5997

REFERENCES

url:http://jvn.jp/en/jp/jvn65312543/index.html

Trust: 3.1

url:http://jvndb.jvn.jp/jvndb/jvndb-2013-000109

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-5997

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-5997

Trust: 0.8

url:http://jvndb.jvn.jp/en/contents/2013/jvndb-2013-000109.html

Trust: 0.6

sources: CNVD: CNVD-2013-14707 // VULHUB: VHN-65999 // JVNDB: JVNDB-2013-000109 // CNNVD: CNNVD-201311-362 // NVD: CVE-2013-5997

CREDITS

Hisashi Kojima and Masahiro Nakada of Fujitsu Laboratories

Trust: 0.3

sources: BID: 63871

SOURCES

db:CNVDid:CNVD-2013-14707
db:VULHUBid:VHN-65999
db:BIDid:63871
db:JVNDBid:JVNDB-2013-000109
db:CNNVDid:CNNVD-201311-362
db:NVDid:CVE-2013-5997

LAST UPDATE DATE

2025-04-11T23:05:35.001000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-14707date:2013-11-26T00:00:00
db:VULHUBid:VHN-65999date:2014-03-07T00:00:00
db:BIDid:63871date:2013-11-22T00:00:00
db:JVNDBid:JVNDB-2013-000109date:2013-11-26T00:00:00
db:CNNVDid:CNNVD-201311-362date:2013-11-29T00:00:00
db:NVDid:CVE-2013-5997date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-14707date:2013-11-26T00:00:00
db:VULHUBid:VHN-65999date:2013-11-22T00:00:00
db:BIDid:63871date:2013-11-22T00:00:00
db:JVNDBid:JVNDB-2013-000109date:2013-11-22T00:00:00
db:CNNVDid:CNNVD-201311-362date:2013-11-29T00:00:00
db:NVDid:CVE-2013-5997date:2013-11-22T19:55:09.437