vendor:
Aerohive HiveOS
by:
LiquidWorm
5.5
CVSS
MEDIUM
Remote Denial of Service
400
CWE
Product Name: Aerohive HiveOS
Affected Version From: 11.x
Affected Version To: 11.x
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2020
Extreme Networks Aerohive HiveOS 11.0 – Remote Denial of Service (PoC)
An unauthenticated malicious user can trigger a Denial of Service (DoS) attack when sending specific application layer packets towards the Aerohive NetConfig UI. This PoC exploit renders the application unusable for 305 seconds or 5 minutes with a single HTTP request using the action.php5 script calling the CliWindow function thru the _page parameter, denying access to the web server hive user interface.
Mitigation:
Vendor mitigation: CLI> no system web-server hive-ui enable