CVE-2019-5108

Advisory lineage Upstream: 0 Downstream: 20
Modified
Published: 23 Dec 2019, 18:55
Last modified:04 Aug 2024, 19:47

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.4 HIGH
v3.0 (cve.org)
EPSS Score
0.76% LOW
1% probability +0.08%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

23 Dec 2019, 18:55
Published
Vulnerability first disclosed
04 Aug 2024, 19:47
Last Modified
Vulnerability information updated

Description

An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial-of-service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby APs of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.0HIGHScore: 7.4CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • v2.0LOWScore: 3.3AV:A/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.76% Percentile: 74%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

  • CWE-440Expected Behavior Violation

    A feature, API, or function does not perform according to its specification.

Affected Systems

  • canonicalubuntu_linux

    14.04 | 16.04 | 18.04

  • debiandebian_linux

    8.0 | 9.0

  • linuxlinux_kernel

    < 5.3

  • netapp8300_firmware

    na

  • netapp8700_firmware

    na

  • netappa400_firmware

    na

  • netappa700s_firmware

    na

  • netappactive_iq_unified_manager

    na

  • netappcloud_backup

    na

  • netappdata_availability_services

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.70.1

  • netapph610s_firmware

    na

  • netapphci_management_node

    na

  • netappsolidfire

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • oraclesd-wan_edge

    8.2

References (14)