vendor:
NetworkSleuth
by:
Alejandra Sánchez
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: NetworkSleuth
Affected Version From: 3.0.0.0
Affected Version To: 3.0.0.0
Patch Exists: NO
Related CWE: N/A
CPE: a:nsauditor:networksleuth:3.0.0.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2019
NetworkSleuth 3.0 – Denial of Service (PoC)
NetworkSleuth 3.0 is vulnerable to a Denial of Service attack when a maliciously crafted string is entered into the 'Name' field of the 'Enter Registration Code' window. When the 'Ok' button is clicked, the application crashes.
Mitigation:
Users should avoid entering untrusted input into the 'Name' field of the 'Enter Registration Code' window.