vendor:
Nmap
by:
Gionathan 'John' Reale
9.8
CVSS
CRITICAL
Denial of Service
20
CWE
Product Name: Nmap
Affected Version From: 7.70
Affected Version To: 7.70
Patch Exists: YES
Related CWE: CVE-2018-7600
CPE: nmap:nmap
Other Scripts:
N/A
Platforms Tested: Windows 7 32bit
2018
Nmap 7.70 – Denial of Service (PoC)
This vulnerability causes the program to crash and start to heavily consume system resources. Do not test on critical systems, can cause system crash. Steps to reproduce: 1. Create a file in Notepad with the given XML code and save it as 'test.xml'. 2. Run the command 'nmap --script-args=unsafe=1 -sV -p80 --script http-vuln-cve2018-7600 test.xml'. 3. The program will crash and start to heavily consume system resources.
Mitigation:
Ensure that the system is updated with the latest security patches and that the system is configured to use the latest security protocols.