vendor:
AbsoluteTelnet
by:
chuyreds
7.5
CVSS
HIGH
Denial of Service (DoS) Local
CWE
Product Name: AbsoluteTelnet
Affected Version From: 11.12
Affected Version To: 11.12
Patch Exists: NO
Related CWE:
CPE: a:celestialsoftware:absolute_telnet:11.12
Platforms Tested: Windows 10 Pro x64 es
2020
AbsoluteTelnet 11.12 – ‘SSH1/username’ Denial of Service (PoC)
The AbsoluteTelnet version 11.12 is vulnerable to a denial of service (DoS) attack. By sending a specially crafted payload to the SSH1 'username' field, an attacker can cause the application to crash, resulting in a denial of service condition.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability. It is recommended to avoid using AbsoluteTelnet version 11.12 or update to a newer version if available.