vendor:
NVR3 Standard or Professional Server
by:
MegaMagnus
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: NVR3 Standard or Professional Server
Affected Version From: V.3.0.12.42
Affected Version To: V.2.3.04.07
Patch Exists: YES
Related CWE: CVE-2020-15956
CPE: a:acti:nvr3_standard_or_professional_server:3.0.12.42
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7, Windows 10
2020
ACTi NVR3 Standard or Professional Server 3.0.12.42 – Denial of Service (PoC)
This is a Proof of Concept Exploit which can be used to cause a Denial of Service on ACTi NVR3 Standard or Professional Server 3.0.12.42. The exploit sends a specially crafted HTTP request with an authentication header containing a large number of null bytes. This causes the server to crash.
Mitigation:
The vendor has released a patch to address this vulnerability.