René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

107 lines
3.3 KiB
JSON

{
"id": "CVE-2017-14114",
"sourceIdentifier": "cve@mitre.org",
"published": "2017-09-02T16:29:00.363",
"lastModified": "2017-09-19T17:33:45.293",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "RTPproxy through 2.2.alpha.20160822 has a NAT feature that results in not properly determining the IP address and port number of the legitimate recipient of RTP traffic, which allows remote attackers to obtain sensitive information or cause a denial of service (communication outage) via crafted RTP packets."
},
{
"lang": "es",
"value": "RTPproxy hasta la versi\u00f3n 2.2.alpha.20160822 tiene una caracter\u00edstica NAT que resulta en que no se determina correctamente la direcci\u00f3n IP y el n\u00famero de puerto del destinatario leg\u00edtimo de tr\u00e1fico RTP, lo que permite que atacantes remotos obtengan informaci\u00f3n sensible o provoquen una denegaci\u00f3n de servicio (interrupci\u00f3n de la comunicaci\u00f3n) mediante paquetes RTP manipulados."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "LOW",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 2.5
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 6.4
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:rtpproxy:rtpproxy:*:alpha.20160822:*:*:*:*:*:*",
"versionEndIncluding": "2.2",
"matchCriteriaId": "4529ABC9-0034-496E-98E9-E21976F96893"
}
]
}
]
}
],
"references": [
{
"url": "https://rtpbleed.com",
"source": "cve@mitre.org",
"tags": [
"Press/Media Coverage",
"Technical Description",
"Third Party Advisory"
]
}
]
}