Apple AirPort Base Station (802.11n) Firmware < 7.6.4 Remote DoS (APPLE-SA-2013-09-06-1)

medium Nessus Plugin ID 69817

Synopsis

The remote network device is affected by a denial of service vulnerability.

Description

According to the firmware version collected via SNMP, the remote AirPort Extreme Base Station / AirPort Express Base Station / Apple Time Capsule reportedly does not properly parse small frames with incorrect lengths. An associated client might be able to leverage this vulnerability to cause a termination of the base station system.

Solution

Upgrade the firmware to version 7.6.4 or later.

See Also

https://support.apple.com/en-us/HT202800

https://lists.apple.com/archives/security-announce/2013/Sep/msg00000.html

https://www.securityfocus.com/archive/1/528462/30/0/threaded

Plugin Details

Severity: Medium

ID: 69817

File Name: airport_firmware_7_6_4.nasl

Version: 1.4

Type: local

Family: Misc.

Published: 9/9/2013

Updated: 11/27/2019

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2013-5132

Vulnerability Information

Required KB Items: Host/Airport/Firmware, SNMP/community

Exploit Ease: No known exploits are available

Patch Publication Date: 8/13/2013

Vulnerability Publication Date: 9/6/2013

Reference Information

CVE: CVE-2013-5132

BID: 62262

APPLE-SA: APPLE-SA-2013-09-06-1