header-logo
Suggest Exploit
vendor:
602 LAN SUITE
by:
7.5
CVSS
HIGH
Denial of Service
399
CWE
Product Name: 602 LAN SUITE
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: Windows

Multiple Denial of Service Vulnerabilities in 602 LAN SUITE

602 LAN SUITE is prone to multiple remote denial of service vulnerabilities. The first vulnerability allows an attacker to consume CPU and memory resources on a target server due to a lack of sanity checking before memory allocation. The second vulnerability is related to the telnet proxy requests handling, where the proxy does not perform sufficient sanity checks on the destination IP, allowing a remote attacker to exhaust all available sockets on the target computer.

Mitigation:

No official patch or mitigation is available at the moment. It is recommended to disable the affected software or implement network-level mitigations.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/11615/info

602 LAN SUITE is reported prone to multiple remote denial of service vulnerabilities. The following specific issues are reported:

It is reported that an attacker may consume CPU and memory resources on a target 602 LAN SUITE server. Reports indicate that this condition exists due to a lack of sanity checking prior to the allocation of regions of memory by the affected software. 

A remote attacker may exploit this vulnerability to consume system resources, ultimately impacting the performance of the target computer and potentially resulting in a denial of service.

A second vulnerability is reported in the manner in which 602 LAN SUITE handles telnet proxy requests. It is reported that the proxy does not perform sufficient sanity checks on the destination IP of a proxy request.

A remote attacker may exploit this condition to exhaust all available sockets on a target computer that is running 602 LAN SUITE telnet proxy. This will effectively deny service to legitimate requests.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/24726.zip