vendor:
NetDecision HTTP Server
by:
Prabhu S Angadi
5,5
CVSS
MEDIUM
Denial Of Service
N/A
CWE
Product Name: NetDecision HTTP Server
Affected Version From: Netmechanica NetDecision 4.5.1 (full package)
Affected Version To: Netmechanica NetDecision 4.5.1 (full package)
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 & Win XP2
2011
Netmechanica NetDecision HTTP Server Denial Of Service Vulnerability
Netmechanica NetDecision HTTP Server version 4.5.1 is prone to a denial of service vulnerability. The vulnerability is caused due to improper validation of long malicious HTTP request to web server, which allows remote attackers to crash the service.
Mitigation:
Validate user input and limit the length of the HTTP request.