Denial of Service Vulnerability in Unisys Libra Systems
CVE-2017-13684

7.8HIGH

Key Information:

Vendor

Unisys

Vendor
CVE Published:
30 September 2017

What is CVE-2017-13684?

Certain Unisys Libra systems, specifically the 64xx and 84xx series and FS601 class systems running MCP-FIRMWARE prior to version 43.211, are susceptible to a vulnerability that allows remote authenticated users to exploit improper handling of literals. This exploitation can lead to a denial of service, resulting in program crashes and other unspecified impacts related to stack corruption within the CPM. It is critical for users of these systems to ensure that they have updated their firmware to mitigate these risks.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.