MEDIUM · 5.0

CVE-2010-2090

The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attacke...

Vulnerability Description

The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attackers to cause a denial of service (daemon crash) via APPC data containing a GDSID variable with a GDS length that is too small.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
MicrosoftWindowsAll versions
IbmCommunications Server6.1.3
IbmAixAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2090?

CVE-2010-2090 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attacke...

How severe is CVE-2010-2090?

CVE-2010-2090 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2090?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows, Ibm Communications Server, Ibm Aix.