Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-9750

EPSS 0.28% · P51
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-9750

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In IoTivity through 1.3.1, the CoAP server interface can be used for Distributed Denial of Service attacks using source IP address spoofing and UDP-based traffic amplification. The reflected traffic is 6 times bigger than spoofed requests. This occurs because the construction of a "4.01 Unauthorized" response is mishandled. NOTE: the vendor states "While this is an interesting attack, there is no plan for maintainer to fix, as we are migrating to IoTivity Lite."
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IoTivity 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IoTivity是一个支持设备与设备互联的物联网框架。 IoTivity 1.3.1及之前版本中存在输入验证漏洞。攻击者可利用该漏洞造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2019-9750

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-9750

Please Login to view more intelligence information

Same Patch Batch · n/a · 2019-03-13 · 18 CVEs total

CVE-2019-9746libwebm 安全漏洞
CVE-2019-9738jimmykuu Gopher 跨站脚本漏洞
CVE-2019-9737Editor.md 跨站脚本漏洞
CVE-2019-97361024Tools Markdown 跨站脚本漏洞
CVE-2019-9735OpenStack Neutron 安全特征问题漏洞
CVE-2019-9740Python 注入漏洞
CVE-2019-9741Google Go 注入漏洞
CVE-2018-20621Microvirt MEmu 权限许可和访问控制漏洞
CVE-2019-9742G DATA Software Total Security 安全特征问题漏洞
CVE-2018-20800Open Ticket Request System 输入验证漏洞
CVE-2015-2254Huawei OceanStor UDS 信息泄露漏洞
CVE-2019-9749Fluent Bit 输入验证错误漏洞
CVE-2019-9748tinysvcmdns 安全漏洞
CVE-2019-9747tinysvcmdns 输入验证错误漏洞
CVE-2019-9754Tiny C Compiler 安全漏洞
CVE-2019-9752OTRS Open Ticket Request System 跨站脚本漏洞
CVE-2019-9751Open Ticket Request System 跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2019-9750

No comments yet


Leave a comment