ID

VAR-201912-2010


TITLE

Denial of service vulnerability in ZLAN5102 and ZLAN5103 network cards

Trust: 0.6

sources: CNVD: CNVD-2019-44109

DESCRIPTION

ZLAN5102 serial server is a protocol converter between RS232 / 485 and TCP / IP developed by Shanghai Zhuolan Information Technology Co., Ltd. The serial server can conveniently connect serial devices to Ethernet and the Internet, and realize the network upgrade of serial devices. ZLAN5103 is a new generation high-performance serial server developed by Shanghai Zhuolan based on ZLAN1003. The ZLAN5102 and ZLAN5103 network cards have a denial of service vulnerability. Sending only three-way TCP handshake packets to port 80 of the device and no other packets will cause the device's network card to restart abnormally. An attacker could use the vulnerability to launch a denial of service attack.

Trust: 0.6

sources: CNVD: CNVD-2019-44109

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-44109

AFFECTED PRODUCTS

vendor:zhuolan informationmodel:zlan network cardscope:eqversion:v5102

Trust: 0.6

vendor:zhuolan informationmodel:zlan network cardscope:eqversion:v5103

Trust: 0.6

sources: CNVD: CNVD-2019-44109

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-44109
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2019-44109
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2019-44109

PATCH

title:Denial of service vulnerability in ZLAN5102 and ZLAN5103 network cardsurl:https://www.cnvd.org.cn/patchinfo/show/189505

Trust: 0.6

sources: CNVD: CNVD-2019-44109

EXTERNAL IDS

db:CNVDid:CNVD-2019-44109

Trust: 0.6

sources: CNVD: CNVD-2019-44109

SOURCES

db:CNVDid:CNVD-2019-44109

LAST UPDATE DATE

2022-05-04T10:00:05.367000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-44109date:2019-12-10T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-44109date:2019-12-26T00:00:00