ID

VAR-201808-0497


CVE

CVE-2018-15352


TITLE

Kraftway 24F2XG Router Firmware vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2018-009339

DESCRIPTION

An attacker with low privileges can cause denial of service in Kraftway 24F2XG Router firmware version 3.5.30.1118. Kraftway 24F2XG Router There are unspecified vulnerabilities in the firmware.Service operation interruption (DoS) There is a possibility of being put into a state. Kraftway24F2XGRouter is a wireless router product from Kraftway, Russia

Trust: 2.25

sources: NVD: CVE-2018-15352 // JVNDB: JVNDB-2018-009339 // CNVD: CNVD-2018-16289 // VULHUB: VHN-125603

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-16289

AFFECTED PRODUCTS

vendor:kraftwaymodel:24f2xg routerscope:eqversion:3.5.30.1118

Trust: 2.4

vendor:kraftwaymodel:24f2xgscope:eqversion:3.5.30.1118

Trust: 0.6

sources: CNVD: CNVD-2018-16289 // JVNDB: JVNDB-2018-009339 // CNNVD: CNNVD-201808-553 // NVD: CVE-2018-15352

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-15352
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-15352
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2018-16289
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201808-553
value: MEDIUM

Trust: 0.6

VULHUB: VHN-125603
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-15352
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-16289
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-125603
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-15352
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-16289 // VULHUB: VHN-125603 // JVNDB: JVNDB-2018-009339 // CNNVD: CNNVD-201808-553 // NVD: CVE-2018-15352

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2018-15352

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201808-553

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-201808-553

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-009339

PATCH

title:Top Pageurl:https://www.kraftway.ru/

Trust: 0.8

sources: JVNDB: JVNDB-2018-009339

EXTERNAL IDS

db:NVDid:CVE-2018-15352

Trust: 3.1

db:JVNDBid:JVNDB-2018-009339

Trust: 0.8

db:CNNVDid:CNNVD-201808-553

Trust: 0.7

db:CNVDid:CNVD-2018-16289

Trust: 0.6

db:VULHUBid:VHN-125603

Trust: 0.1

sources: CNVD: CNVD-2018-16289 // VULHUB: VHN-125603 // JVNDB: JVNDB-2018-009339 // CNNVD: CNNVD-201808-553 // NVD: CVE-2018-15352

REFERENCES

url:https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/08/17/klcert-18-008-kraftway-24f2xg-router-denial-of-service/

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2018-15352

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-15352

Trust: 0.8

sources: CNVD: CNVD-2018-16289 // VULHUB: VHN-125603 // JVNDB: JVNDB-2018-009339 // CNNVD: CNNVD-201808-553 // NVD: CVE-2018-15352

SOURCES

db:CNVDid:CNVD-2018-16289
db:VULHUBid:VHN-125603
db:JVNDBid:JVNDB-2018-009339
db:CNNVDid:CNNVD-201808-553
db:NVDid:CVE-2018-15352

LAST UPDATE DATE

2024-11-23T23:04:59.537000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-16289date:2018-08-27T00:00:00
db:VULHUBid:VHN-125603date:2018-10-23T00:00:00
db:JVNDBid:JVNDB-2018-009339date:2018-11-16T00:00:00
db:CNNVDid:CNNVD-201808-553date:2021-06-27T00:00:00
db:NVDid:CVE-2018-15352date:2024-11-21T03:50:36.247

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-16289date:2018-08-27T00:00:00
db:VULHUBid:VHN-125603date:2018-08-17T00:00:00
db:JVNDBid:JVNDB-2018-009339date:2018-11-16T00:00:00
db:CNNVDid:CNNVD-201808-553date:2018-08-20T00:00:00
db:NVDid:CVE-2018-15352date:2018-08-17T14:29:00.543