CVE-2019-15513
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/08/2019
Last modified:
07/11/2023
Description
An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a device hang.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openwrt:libuci:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:motorola:cx2l_mwr04l_firmware:1.01:*:*:*:*:*:*:* | ||
| cpe:2.3:h:motorola:cx2l_mwr04l:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:motorola:c1_mwr03_firmware:1.01:*:*:*:*:*:*:* | ||
| cpe:2.3:h:motorola:c1_mwr03:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.openwrt.org/?p=project/uci.git%3Ba%3Dcommitdiff%3Bh%3D19e29ffc15dbd958e8e6a648ee0982c68353516f
- https://github.com/TeamSeri0us/pocs/blob/master/iot/morouter/motorola%E8%B7%AF%E7%94%B1%E5%99%A8%E6%96%87%E4%BB%B6%E8%A7%A3%E9%94%81%E6%BC%8F%E6%B4%9E.pdf
- https://lists.infradead.org/pipermail/openwrt-devel/2019-November/019736.html
- https://lists.openwrt.org/pipermail/openwrt-devel/2019-November/025453.html



