CVE-2011-3992
Buffer overflow in the SSH server functionality on the D-Link DES-3800 with firmware before 4.50B052, DWL-2100AP with firmware before 2.50RC548, and DWL-3200AP with firmware before 2.55RC549 allows remote attackers to execute arbitrary code or cause a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.46%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in the SSH server functionality on the D-Link DES-3800 with firmware before 4.50B052, DWL-2100AP with firmware before 2.50RC548, and DWL-3200AP with firmware before 2.55RC549 allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.46% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- dlink/des-3800 · dlink/des-3800 firmware · dlink/dwl-2100ap · dlink/dwl-2100ap firmware · dlink/dwl-3200ap · dlink/dwl-3200ap firmware
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN72640744/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-000092
- http://osvdb.org/76628
- http://www.dlink-jp.com/page/sc/F/security_info20111028.html
- http://www.securityfocus.com/bid/50405
- http://jvn.jp/en/jp/JVN72640744/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-000092
- http://osvdb.org/76628
- http://www.dlink-jp.com/page/sc/F/security_info20111028.html
- http://www.securityfocus.com/bid/50405
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.