CVE-2008-5421
Published Dec 11, 2008
Last updated 16 years ago
Overview
- Description
- The SSL web administration service in NetWin SmsGate 1.1n and earlier allows remote attackers to cause a denial of service (hang) via (1) a large integer in the Content-Length HTTP header; (2) an invalid value in the Content-Length HTTP header, as demonstrated by a negative integer; or (3) a missing Content-Length HTTP header.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-399
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:netwin:smsgate:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2211287-71BF-4E35-B85E-58847DBA353A", "versionEndIncluding": "1.1n" }, { "criteria": "cpe:2.3:a:netwin:smsgate:1.0a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B4EF5AA8-607A-4C3C-8F9A-804AFEF118AB" }, { "criteria": "cpe:2.3:a:netwin:smsgate:1.0c:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C1E2964-06AA-46E8-8203-8A362A8FA35F" }, { "criteria": "cpe:2.3:a:netwin:smsgate:1.0h:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E0B695B-6A9D-4637-864D-9D13F0A97CCF" }, { "criteria": "cpe:2.3:a:netwin:smsgate:1.0r:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "519E1CBF-547A-4982-83D2-92237E747B6B" }, { "criteria": "cpe:2.3:a:netwin:smsgate:1.0w:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A9D52FB-66DC-4E01-B8C9-EA173469CDC6" }, { "criteria": "cpe:2.3:a:netwin:smsgate:1.1m:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F582AD2E-5954-49E2-B786-A082C7027FCF" } ], "operator": "OR" } ] } ]