CVE-2019-9750 Information
Feb 14, 2021
cve
Description
In IoTivity through 1.3.1 the CoAP server interface can be used for Distributed Denial of Service attacks using source IP address spoofing and UDP-based traffic amplification. The reflected traffic is 6 times bigger than spoofed requests. This occurs because the construction of a \4.01 Unauthorized\ response is mishandled. NOTE: the vendor states \While this is an interesting attack there is no plan for maintainer to fix as we are migrating to IoTivity Lite.\
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Reference
https://jira.iotivity.org/browse/IOT-3267
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.1
Share on: