vendor:
Disk Pulse Enterprise
by:
Daniel Teixeira
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Disk Pulse Enterprise
Affected Version From: 10.4.16
Affected Version To: 10.4.18
Patch Exists: YES
Related CWE: CVE-2017-7310
CPE: a:diskpulse:disk_pulse_enterprise:10.4.18
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 SP1 x86
2018
Disk Pulse Enterprise v10.4.18 – ‘Import Command’ Buffer Overflow (SEH)
Disk Pulse Enterprise v10.4.18 is vulnerable to a buffer overflow vulnerability in the 'Import Command' feature. An attacker can exploit this vulnerability by sending a specially crafted XML file to the application, which can lead to arbitrary code execution. The vulnerability is caused due to a boundary error when handling the 'name' parameter of the 'classify' tag in the XML file.
Mitigation:
Upgrade to the latest version of Disk Pulse Enterprise v10.4.18 or later.