MEDIUM · 6.5

CVE-2018-18508

In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.

Vulnerability Description

In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
MozillaNetwork Security Services< 3.36.7
SiemensRuggedcom Rox Mx5000 Firmware< 2.14.0
SiemensRuggedcom Rox Mx5000-
SiemensRuggedcom Rox Rx1400 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1400-
SiemensRuggedcom Rox Rx1500 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1500-
SiemensRuggedcom Rox Rx1501 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1501-
SiemensRuggedcom Rox Rx1510 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1510-
SiemensRuggedcom Rox Rx1511 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1511-
SiemensRuggedcom Rox Rx1512 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1512-
SiemensRuggedcom Rox Rx5000 Firmware< 2.14.0
SiemensRuggedcom Rox Rx5000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-18508?

CVE-2018-18508 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.

How severe is CVE-2018-18508?

CVE-2018-18508 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-18508?

Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Network Security Services, Siemens Ruggedcom Rox Mx5000 Firmware, Siemens Ruggedcom Rox Mx5000, Siemens Ruggedcom Rox Rx1400 Firmware, Siemens Ruggedcom Rox Rx1400.