Vulnerabilities > CVE-2013-5132 - Numeric Errors vulnerability in Apple Airport Base Station Firmware
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Apple AirPort Base Station Firmware before 7.6.4 does not properly handle incorrect frame lengths, which allows remote attackers to cause a denial of service (device crash) by associating with the access point and then sending a short frame.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | Misc. |
NASL id | AIRPORT_FIRMWARE_7_6_4.NASL |
description | According to the firmware version collected via SNMP, the remote AirPort Extreme Base Station / AirPort Express Base Station / Apple Time Capsule reportedly does not properly parse small frames with incorrect lengths. An associated client might be able to leverage this vulnerability to cause a termination of the base station system. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 69817 |
published | 2013-09-09 |
reporter | This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/69817 |
title | Apple AirPort Base Station (802.11n) Firmware < 7.6.4 Remote DoS (APPLE-SA-2013-09-06-1) |
code |
|
Seebug
bulletinFamily | exploit |
description | CVE(CAN) ID: CVE-2013-5132 Apple Time Capsule是无线的附加到网络的存储设备,组合了Apple生产的无线内置网关路由。Apple AirPort Extreme是针对家庭、学校和小型企业的无线解决方案。 Apple AirPort、Time Capsule 7.6.4之前版本在处理帧时存在错误,本地攻击者发送长度不正确的特制小帧,利用此漏洞可造成意外基站系统中断,导致拒绝服务。 0 Apple Time Capsule < 7.6.4 Apple AirPort Express Firmware < 7.6.4 厂商补丁: Apple ----- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: http://www.apple.com/support/downloads/ |
id | SSV:60998 |
last seen | 2017-11-19 |
modified | 2013-09-13 |
published | 2013-09-13 |
reporter | Root |
title | Apple AirPort / Time Capsule 帧处理拒绝服务漏洞 |