vendor:
QVR Client
by:
Luis Martínez
7.5
CVSS
HIGH
Denial of Service (DoS) Local
CWE
Product Name: QVR Client
Affected Version From: 5.1.1.30070
Affected Version To: 5.1.1.30070
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro x64 es
2018
QNap QVR Client 5.1.1.30070 – ‘Password’ Denial of Service (PoC)
The QNap QVR Client version 5.1.1.30070 is vulnerable to a denial of service attack when a specially crafted password is provided. By sending a large buffer of 'A' characters, the application crashes, resulting in a denial of service condition.
Mitigation:
Upgrade to a patched version of the QNap QVR Client software.