vendor:
ApowerManager - Phone Manager
by:
Marcelo Vázquez (aka s4vitar)
7.5
CVSS
HIGH
Remote Denial of Service (DoS)
20
CWE
Product Name: ApowerManager - Phone Manager
Affected Version From: 3.1.7 and earlier
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: a:apowersoft:apowermanager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Android
2019
ApowerManager – Phone Manager Remote Denial of Service (DoS) / Application Crash
A vulnerability in ApowerManager - Phone Manager version 3.1.7 and earlier allows an attacker to cause a denial of service (DoS) or application crash by sending a crafted request to the application. The vulnerability exists due to insufficient validation of user-supplied input when processing requests to the application. An attacker can send a malicious request to the application to trigger this vulnerability.
Mitigation:
Upgrade to the latest version of ApowerManager - Phone Manager.