CVE-2016-6567 Information
Feb 14, 2021
cve
Description
SHDesigns’ Resident Download Manager provides firmware update capabilities for Rabbit 2000/3000 CPU boards which according to the reporter may be used in some industrial control and embedded applications. The Resident Download Manager does not verify that the firmware is authentic before executing code and deploying the firmware to devices. A remote attacker with the ability to send UDP traffic to the device may be able to execute arbitrary code on the device. According to SHDesigns’ website the Resident Download Manager and other Rabbit Tools have been discontinued since June 2011.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/95898 https://www.kb.cert.org/vuls/id/167623
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: