HIGH · 7.8

CVE-2009-0396

The Sony Ericsson W910i, W660i, K618i, K610i, Z610i, K810i, K660i, W880i, and K530i phones allow remote attackers to cause a denial of service (device reboot or hang-up) via a malformed WAP Push packe...

Vulnerability Description

The Sony Ericsson W910i, W660i, K618i, K610i, Z610i, K810i, K660i, W880i, and K530i phones allow remote attackers to cause a denial of service (device reboot or hang-up) via a malformed WAP Push packet to (1) SMS or (2) UDP port 2948.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
Sony EricssonK530IAll versions
Sony EricssonK610IAll versions
Sony EricssonK618IAll versions
Sony EricssonK660IAll versions
Sony EricssonK810IAll versions
Sony EricssonW660IAll versions
Sony EricssonW880IAll versions
Sony EricssonW910IAll versions
Sony EricssonZ610IAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-0396?

CVE-2009-0396 is a vulnerability with a CVSS score of 7.8 (HIGH). The Sony Ericsson W910i, W660i, K618i, K610i, Z610i, K810i, K660i, W880i, and K530i phones allow remote attackers to cause a denial of service (device reboot or hang-up) via a malformed WAP Push packe...

How severe is CVE-2009-0396?

CVE-2009-0396 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0396?

Check the references section above for vendor advisories and patch information. Affected products include: Sony Ericsson K530I, Sony Ericsson K610I, Sony Ericsson K618I, Sony Ericsson K660I, Sony Ericsson K810I.