vendor:
Policy Manager Server
by:
David Maciejak
7.5
CVSS
HIGH
Remote denial-of-service vulnerability
CWE
Product Name: Policy Manager Server
Affected Version From: Versions of F-Secure Policy Manager prior to 7.01
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
F-Secure Policy Manager Server fsmsh.dll module DoS
The F-Secure Policy Manager Server is vulnerable to a denial-of-service attack. A malicious user can send a forged request to query a MS-DOS device name through the fsmsh.dll CGI module, causing the service to stop responding to legitimate users.
Mitigation:
Not available for now.