CVE-2009-3115: Input Validation
Published Sep 9, 2009
·Updated
SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a crafted Option Acknowledgement (OACK) request. NOTE: some of these details are obtained from third party information.
Affected Software
5 affected components
SolarWinds TFTP Server<=9.2.0.111
SolarWinds TFTP Server=5.0.55
SolarWinds TFTP Server=5.0.60
SolarWinds TFTP Server=8.1
SolarWinds TFTP Server=8.2
Event History
Sep 9, 2009
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3115?
CVE-2009-3115 is classified as a denial of service vulnerability.
2
How do I fix CVE-2009-3115?
To fix CVE-2009-3115, upgrade to a version of SolarWinds TFTP Server that is later than 9.2.0.111.
3
What versions of SolarWinds TFTP Server are affected by CVE-2009-3115?
CVE-2009-3115 affects all versions of SolarWinds TFTP Server up to and including 9.2.0.111.
4
Can CVE-2009-3115 be exploited remotely?
Yes, CVE-2009-3115 can be exploited by remote attackers via a specially crafted Option Acknowledgement request.
5
What are the potential consequences of exploiting CVE-2009-3115?
Exploitation of CVE-2009-3115 can lead to a denial of service, causing the SolarWinds TFTP Server to stop functioning.