Input validation error in DHCP - CVE-2019-6470
Published: August 20, 2019
Vulnerability identifier: #VU20341
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6470
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a double deletion issue of released addresses in the DHCPv6 code. A remote non-authenticated attacker can send specially crafted DHCP message to the affected system and perform denial of service attack.
Affected software
DHCP
Dell EMC PowerProtect Data Protection
Data Computing Appliance (DCA)
SmartFabric OS10
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Opensuse
Dell EMC PowerProtect Data Protection
Data Computing Appliance (DCA)
SmartFabric OS10
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for x86_64
Opensuse
How to mitigate CVE-2019-6470
Install updates from vendor's website.
DHCP - update to 4.4.1
Dell EMC PowerProtect Data Protection - update to 2.7.8
Data Computing Appliance (DCA) - update to 4.3.0.0
SmartFabric OS10 - update to 10.5.6.1
Dell EMC PowerProtect Data Protection - update to 2.7.8
Data Computing Appliance (DCA) - update to 4.3.0.0
SmartFabric OS10 - update to 10.5.6.1
External References
Related Security Bulletins
- Denial of service in ISC DHCP
- Red Hat update for dhcp
- OpenSUSE Linux update for dhcp
- OpenSUSE Linux update for dhcp
- Red Hat update for dhcp
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in Dell Networking OS10
- PowerProtect Data Protection software update for third-party components