vendor:
Disk Pulse Enterprise
by:
Anurag Srivastava
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Disk Pulse Enterprise
Affected Version From: 9.9.16
Affected Version To: 9.9.16
Patch Exists: YES
Related CWE: N/A
CPE: a:diskpulse:disk_pulse_enterprise:9.9.16
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 Ultimate x64bit and Windows 10 Home Edition x64
2017
Disk Pulse Enterprise 9.9.16 – ‘Import Command’ Buffer Overflow
Disk Pulse Enterprise 9.9.16 is vulnerable to a buffer overflow vulnerability when importing a specially crafted XML file. An attacker can exploit this vulnerability by creating a malicious XML file and then importing it into the application. This will cause a buffer overflow and allow the attacker to execute arbitrary code on the target system.
Mitigation:
Update to the latest version of Disk Pulse Enterprise 9.9.16 or later.