vendor:
NIMax
by:
LinxzSec
7.5
CVSS
HIGH
Local Denial of Service (DoS)
CWE
Product Name: NIMax
Affected Version From: 5.3.1f0
Affected Version To: 5.3.1f0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro x64
2021
NIMax 5.3.1f0 – ‘VISA Alias’ Denial of Service (PoC)
The NIMax software version 5.3.1f0 is vulnerable to a local denial of service (DoS) attack. By adding a specially crafted alias and triggering the 'ok' button, the application crashes, resulting in a denial of service condition. This PoC demonstrates the vulnerability by creating a file with a large number of 'A' characters and using it as a resource name.
Mitigation:
No official patch or mitigation is available at the time of this writing. It is recommended to avoid using untrusted or maliciously crafted resource names in the NIMax software.