Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header options, which allows remote attackers to cause a denial of service (device reboot) via a crafted option that triggers access to an invalid memory location.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Complete
This CVE is not in the KEV list.
The EPSS score is 0.00693.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Nec
Subscribe
|
Ip38x\/1000
Subscribe
Ip38x\/103
Subscribe
Ip38x\/105
Subscribe
Ip38x\/107e
Subscribe
Ip38x\/1100
Subscribe
Ip38x\/1200
Subscribe
Ip38x\/140
Subscribe
Ip38x\/1500
Subscribe
Ip38x\/200
Subscribe
Ip38x\/2000
Subscribe
Ip38x\/250i
Subscribe
Ip38x\/300
Subscribe
Ip38x\/3000
Subscribe
Ip38x\/52
Subscribe
Ip38x\/55i
Subscribe
Ip38x\/57i
Subscribe
Ip38x\/58i
Subscribe
Ip38x\/sr100
Subscribe
Ip38x\/v700
Subscribe
|
|
Yamaha
Subscribe
|
Rt100i
Subscribe
Rt102i
Subscribe
Rt103i
Subscribe
Rt105e
Subscribe
Rt105i
Subscribe
Rt105p
Subscribe
Rt107e
Subscribe
Rt140e
Subscribe
Rt140f
Subscribe
Rt140i
Subscribe
Rt140p
Subscribe
Rt200i
Subscribe
Rt250i
Subscribe
Rt300i
Subscribe
Rt56v
Subscribe
Rt57i
Subscribe
Rt58i
Subscribe
Rt60w
Subscribe
Rt80i
Subscribe
Rta50i
Subscribe
Rta52i
Subscribe
Rta54i
Subscribe
Rta55i
Subscribe
Rtv700
Subscribe
Rtw65b
Subscribe
Rtw65i
Subscribe
Rtx1000
Subscribe
Rtx1100
Subscribe
Rtx1200
Subscribe
Rtx1500
Subscribe
Rtx2000
Subscribe
Rtx3000
Subscribe
Srt100
Subscribe
|
Configuration 1 [-]
|
Configuration 2 [-]
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-1331 | Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header options, which allows remote attackers to cause a denial of service (device reboot) via a crafted option that triggers access to an invalid memory location. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-09-16T20:43:08.613Z
Reserved: 2011-03-09T00:00:00Z
Link: CVE-2011-1323
No data.
Status : Deferred
Published: 2011-05-09T19:55:03.257
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-1323
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD