CVE-2014-0997
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 6.4%
from disclosure to weapon0 days
Published on NVDSep 25
1st PoCJan 26
exploitation probability
6.4%top 7% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android 4.1.2 as used in the Motorola RAZR HD, and potentially other unspecified Android releases before 5.0.1 and 5.0.2 does not properly handle exceptions, which allows remote attackers to cause a denial of service (reboot) via a crafted 802.11 probe response frame.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/35913cve_referencepacketstormsecurity.com/files/130107/Android-WiFi-Direct-Denial-Of-Service.htmlunverifiedcve_referencewww.exploit-db.com/exploits/35913/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/130107/Android-WiFi-Direct-Denial-Of-Service.htmlhttp://seclists.org/fulldisclosure/2015/Jan/104https://www.coresecurity.com/advisories/android-wifi-direct-denial-servicehttps://www.exploit-db.com/exploits/35913/http://www.securityfocus.com/archive/1/534544/100/0/threadedhttp://www.securityfocus.com/bid/72311