ID

VAR-201812-0714


CVE

CVE-2018-20404


TITLE

VIA Technologies EPIA-E900 Input validation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-014515

DESCRIPTION

ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which calls memmove and constantly fails on an arbitrary (uncontrollable) address, resulting in an eternal hang or a BSoD. VIA Technologies EPIA-E900 Contains an input validation vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. VIA Technologies EPIA-E900 system board is an embedded Pico-ITX motherboard from VIA Technologies. ETK_E900.sys SmartETK driver is one of the drivers. A security vulnerability exists in the ETK_E900.sys SmartETK driver for VIA Technologies EPIA-E900 system motherboards. An attacker could exploit this vulnerability to cause a denial of service

Trust: 1.71

sources: NVD: CVE-2018-20404 // JVNDB: JVNDB-2018-014515 // VULHUB: VHN-131207

AFFECTED PRODUCTS

vendor:viatechmodel:epia-e900scope:eqversion: -

Trust: 1.0

vendor:viamodel:epia e900scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2018-014515 // NVD: CVE-2018-20404

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-20404
value: HIGH

Trust: 1.0

NVD: CVE-2018-20404
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201812-1163
value: HIGH

Trust: 0.6

VULHUB: VHN-131207
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-20404
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-131207
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-20404
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-131207 // JVNDB: JVNDB-2018-014515 // CNNVD: CNNVD-201812-1163 // NVD: CVE-2018-20404

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-131207 // JVNDB: JVNDB-2018-014515 // NVD: CVE-2018-20404

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201812-1163

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-014515

PATCH

title:Top Pageurl:https://www.viatech.com/en/

Trust: 0.8

sources: JVNDB: JVNDB-2018-014515

EXTERNAL IDS

db:NVDid:CVE-2018-20404

Trust: 2.5

db:JVNDBid:JVNDB-2018-014515

Trust: 0.8

db:CNNVDid:CNNVD-201812-1163

Trust: 0.7

db:VULHUBid:VHN-131207

Trust: 0.1

sources: VULHUB: VHN-131207 // JVNDB: JVNDB-2018-014515 // CNNVD: CNNVD-201812-1163 // NVD: CVE-2018-20404

REFERENCES

url:https://downwithup.github.io/cveposts.html

Trust: 2.5

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-20404

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-20404

Trust: 0.8

sources: VULHUB: VHN-131207 // JVNDB: JVNDB-2018-014515 // CNNVD: CNNVD-201812-1163 // NVD: CVE-2018-20404

SOURCES

db:VULHUBid:VHN-131207
db:JVNDBid:JVNDB-2018-014515
db:CNNVDid:CNNVD-201812-1163
db:NVDid:CVE-2018-20404

LAST UPDATE DATE

2024-11-23T22:00:10.327000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-131207date:2019-02-14T00:00:00
db:JVNDBid:JVNDB-2018-014515date:2019-03-25T00:00:00
db:CNNVDid:CNNVD-201812-1163date:2019-02-18T00:00:00
db:NVDid:CVE-2018-20404date:2024-11-21T04:01:25.170

SOURCES RELEASE DATE

db:VULHUBid:VHN-131207date:2018-12-26T00:00:00
db:JVNDBid:JVNDB-2018-014515date:2019-03-25T00:00:00
db:CNNVDid:CNNVD-201812-1163date:2018-12-27T00:00:00
db:NVDid:CVE-2018-20404date:2018-12-26T21:29:02.637