CVE-2019-17006
Last modified
CVE-2019-17006 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.. EPSS estimates a 3.55% chance of exploitation in the next 30 days.
Description
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Ruggedcom Rox Mx5000 Firmware | < 2.14.0 |
| Siemens | Ruggedcom Rox Rx1400 Firmware | < 2.14.0 |
| Siemens | Ruggedcom Rox Rx1500 Firmware | < 2.14.0 |
| Siemens | Ruggedcom Rox Rx1501 Firmware | < 2.14.0 |
| Siemens | Ruggedcom Rox Rx1510 Firmware | < 2.14.0 |
| Siemens | Ruggedcom Rox Rx1511 Firmware | < 2.14.0 |
| Siemens | Ruggedcom Rox Rx1512 Firmware | < 2.14.0 |
| Siemens | Ruggedcom Rox Rx5000 Firmware | < 2.14.0 |
| Mozilla | Network Security Services | < 3.46 |
| Netapp | Hci Management Node | All versions |
| Netapp | Solidfire | All versions |
| Netapp | Hci Compute Node | All versions |
| Netapp | Hci Storage Node | All versions |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1539788Exploit, Issue Tracking, Patch, Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdfThird Party Advisory
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.46_release_notesRelease Notes, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210129-0001/Third Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04Third Party Advisory, US Government Resource
- https://bugzilla.mozilla.org/show_bug.cgi?id=1539788Exploit, Issue Tracking, Patch, Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdfThird Party Advisory
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.46_release_notesRelease Notes, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210129-0001/Third Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-17006?
How severe is CVE-2019-17006?
How do I fix CVE-2019-17006?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1700A vulnerability in field-programmable gate array (FPGA) ingr…6.1
- CVE-2019-17000An object tag with a data URI did not correctly inherit the …6.1
- CVE-2019-17001A Content-Security-Policy that blocks in-line scripts could …6.1
- CVE-2019-17002If upgrade-insecure-requests was specified in the Content Se…4.3
- CVE-2019-17003Scanning a QR code that contained a javascript: URL would ha…6.1
- CVE-2019-17005The plain text serializer used a fixed-size array for the nu…8.8
- CVE-2019-17007In Network Security Services before 3.44, a malformed Netsca…7.5
- CVE-2019-17008When using nested workers, a use-after-free could occur duri…8.8
- CVE-2019-17009When running, the updater service wrote status and log files…7.8
- CVE-2019-1701Multiple vulnerabilities in the WebVPN service of Cisco Adap…4.8
- CVE-2019-17010Under certain conditions, when checking the Resist Fingerpri…7.5
- CVE-2019-17011Under certain conditions, when retrieving a document from a …7.5
Are you affected by CVE-2019-17006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
