CVE-2024-3906
published 2024-04-17CVE-2024-3906: A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file…
PriorityP266high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.66%
73.9th percentile
A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-261142 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | ac500 | — | — |
| tenda | ac500_firmware | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mfvg-qgr4-w7v8: A vulnerability was found in Tenda AC500 2
ghsa_unreviewed·2024-04-17
CVE-2024-3906 [HIGH] CWE-121 GHSA-mfvg-qgr4-w7v8: A vulnerability was found in Tenda AC500 2
A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-261142 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Red Hat
kernel: drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream
vendor_redhat·2024-10-21·CVSS 5.5
CVE-2024-49913 [MEDIUM] CWE-476 kernel: drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream
kernel: drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream
This commit addresses a null pointer dereference issue in the
`commit_planes_for_stream` function at line 4140. The issue could occur
when `top_pipe_to_program` is null.
The fix adds a check to ensure `top_pipe_to_program` is not null before
accessing its stream_res. This prevents a null pointer dereference.
Reported by smatch:
drivers/gpu/drm/amd/amdgpu/../display/dc/core/dc.c:4140 commit_planes_for_stream() error: we previously assumed 'top_pipe_to_program' could be null (see line 3906)
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Suricata
ET MALWARE PlugX Checkin
suricata·2013-11-14
CVE-2013-3906 ET MALWARE PlugX Checkin
ET MALWARE PlugX Checkin
Rule: alert http1 $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE PlugX Checkin"; flow:established,to_server; http.method; content:"POST"; http.uri; pcre:"/^\/[A-F0-9]{24}$/"; http.header; content:"Accept|3a 20 2a 2f 2a 0d 0a|"; startswith; pcre:"/^[A-Z]{4}/R"; content:"1|3a 20|0|0d 0a|"; fast_pattern; within:6; http.header_names; content:!"Referer"; reference:url,fireeye.com/blog/technical/cyber-exploits/2013/11/exploit-proliferation-additional-threat-groups-acquire-cve-2013-3906.html; reference:md5,17f9f999e1814b99601446f8ce7eb816; classtype:command-and-control; sid:2017714; rev:11; metadata:created_at 2013_11_14, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_04_14;)
Suricata
ET MALWARE W32/Citadel.Arx Variant CnC Beacon 1
suricata·2013-11-07
CVE-2013-3906 ET MALWARE W32/Citadel.Arx Variant CnC Beacon 1
ET MALWARE W32/Citadel.Arx Variant CnC Beacon 1
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE W32/Citadel.Arx Variant CnC Beacon 1"; flow:established,to_server; http.uri; content:"/rssfeed.php?a="; fast_pattern; pcre:"/^[^&]+?&\d+$/R"; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,botnetlegalnotice.com/citadel/files/Patel_Decl_Ex20.pdf; reference:url,www.fireeye.com/blog/technical/cyber-exploits/2013/11/the-dual-use-exploit-cve-2013-3906-used-in-both-targeted-attacks-and-crimeware-campaigns.html; classtype:command-and-control; sid:2017690; rev:4; metadata:attack_target Client_Endpoint, created_at 2013_11_07, deployment Perimeter, signature_severity Major, tag c2, updated_at 2024_04_20, mitre_tactic_id TA0010, mitre_tactic_name Exfi
Suricata
ET MALWARE W32/Citadel.Arx Varient CnC Beacon 2
suricata·2013-11-07
CVE-2013-3906 ET MALWARE W32/Citadel.Arx Varient CnC Beacon 2
ET MALWARE W32/Citadel.Arx Varient CnC Beacon 2
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE W32/Citadel.Arx Varient CnC Beacon 2"; flow:established,to_server; http.uri; content:"/psp.php?p="; content:"&g="; content:"&s="; content:"&t="; content:"&r="; http.header_names; to_lowercase; content:!"|0d 0a|referer|0d 0a|"; reference:url,botnetlegalnotice.com/citadel/files/Patel_Decl_Ex20.pdf; reference:url,www.fireeye.com/blog/technical/cyber-exploits/2013/11/the-dual-use-exploit-cve-2013-3906-used-in-both-targeted-attacks-and-crimeware-campaigns.html; classtype:command-and-control; sid:2017691; rev:4; metadata:attack_target Client_Endpoint, created_at 2013_11_07, deployment Perimeter, signature_severity Major, tag c2, updated_at 2024_04_20, mitre_tactic_id TA0010, mitr
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC500/formQuickIndex.mdhttps://vuldb.com/?ctiid.261142https://vuldb.com/?id.261142https://vuldb.com/?submit.313801https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Tenda/AC500/formQuickIndex.mdhttps://vuldb.com/?ctiid.261142https://vuldb.com/?id.261142https://vuldb.com/?submit.313801
2024-04-17
Published