HIGH · 7.5

CVE-2019-17007

In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.

Vulnerability Description

In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
MozillaNetwork Security Services< 3.44
SiemensRuggedcom Rox Mx5000 Firmware< 2.14.0
SiemensRuggedcom Rox Mx5000-
SiemensRuggedcom Rox Rx1400 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1400-
SiemensRuggedcom Rox Rx1500 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1500-
SiemensRuggedcom Rox Rx1501 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1501-
SiemensRuggedcom Rox Rx1510 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1510-
SiemensRuggedcom Rox Rx1511 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1511-
SiemensRuggedcom Rox Rx1512 Firmware< 2.14.0
SiemensRuggedcom Rox Rx1512-
SiemensRuggedcom Rox Rx5000 Firmware< 2.14.0
SiemensRuggedcom Rox Rx5000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-17007?

CVE-2019-17007 is a vulnerability with a CVSS score of 7.5 (HIGH). In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.

How severe is CVE-2019-17007?

CVE-2019-17007 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-17007?

Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Network Security Services, Siemens Ruggedcom Rox Mx5000 Firmware, Siemens Ruggedcom Rox Mx5000, Siemens Ruggedcom Rox Rx1400 Firmware, Siemens Ruggedcom Rox Rx1400.