vendor:
Elipse 3
by:
Mauro Risonho de Paula Assumpção
7,5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: Elipse 3
Affected Version From: 3.x and prior
Affected Version To: 3.x and prior
Patch Exists: YES
Related CWE: CVE-2014-8652
CPE: a:elipse:elipse_3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2013
Exploit Http DoS Request for SCADA ATTACK Elipse 3
Mauro Risonho de Paula Assumpção aka firebits discovered a Denial of Service (DoS) vulnerability in Elipse 3. The vulnerability is caused due to an error in the application when handling a specially crafted HTTP request and can be exploited to cause a hard lock Dll crash in Windows 2003 SP2 with 20 requests connections per second. This vulnerability is identified as CVE-2014-8652.
Mitigation:
Upgrade to the latest version of Elipse 3.