vendor:
IRM License Server
by:
Luigi Auriemma
7,5
CVSS
HIGH
Multiple Vulnerabilities
N/A
CWE
Product Name: IRM License Server
Affected Version From: <= 4.6.1.1995
Affected Version To: <= 4.6.1.1995
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
EMC IRM License Server <= 4.6.1.1995 Remote Exploit
The missing *FIPS fields in the "version compat check" command leads to a NULL pointer in execution. Process freezing caused by some continuous malformed commands, for e.g. sending multiple "version compat check" commands. The server crashes when it receives a command after an invalid version number.
Mitigation:
Upgrade to the latest version of EMC IRM License Server