mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 09:11:28 +00:00
64 lines
3.0 KiB
JSON
64 lines
3.0 KiB
JSON
{
|
|
"id": "CVE-2024-51500",
|
|
"sourceIdentifier": "security-advisories@github.com",
|
|
"published": "2024-11-04T23:15:04.657",
|
|
"lastModified": "2024-11-05T16:04:26.053",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFFFF) which could result in unexpected behavior and potential for DDoS attacks on the network. A malicious actor could craft a packet to be from that address which would result in an amplification of this one message into every node on the network sending multiple messages. Such an attack could result in degraded network performance for all users as the available bandwidth is consumed. This issue has been addressed in release version 2.5.6. All users are advised to upgrade. There are no known workarounds for this vulnerability."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": " El firmware Meshtastic es un firmware de dispositivo para el proyecto Meshtastic. El firmware Meshtastic no comprueba los paquetes que dicen provenir de la direcci\u00f3n de difusi\u00f3n especial (0xFFFFFFFF), lo que podr\u00eda generar un comportamiento inesperado y la posibilidad de ataques DDoS en la red. Un actor malintencionado podr\u00eda crear un paquete que diga que proviene de esa direcci\u00f3n, lo que dar\u00eda como resultado una amplificaci\u00f3n de este mensaje en cada nodo de la red que env\u00ede m\u00faltiples mensajes. Un ataque de este tipo podr\u00eda provocar una degradaci\u00f3n del rendimiento de la red para todos los usuarios, ya que se consume el ancho de banda disponible. Este problema se ha solucionado en la versi\u00f3n 2.5.6. Se recomienda a todos los usuarios que actualicen. No existen workarounds conocidas para esta vulnerabilidad."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "security-advisories@github.com",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
|
|
"baseScore": 5.3,
|
|
"baseSeverity": "MEDIUM",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "LOW"
|
|
},
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 1.4
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "security-advisories@github.com",
|
|
"type": "Secondary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-138"
|
|
},
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-159"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://github.com/meshtastic/firmware/security/advisories/GHSA-xfmq-5j3j-vgv8",
|
|
"source": "security-advisories@github.com"
|
|
}
|
|
]
|
|
} |