vendor:
Axessh
by:
Victor Mondragón
7.8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Axessh
Affected Version From: 4.2
Affected Version To: 4.2
Patch Exists: NO
Related CWE: N/A
CPE: a:labf:axessh:4.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 Service Pack 1 x32
2019
Axessh 4.2 ‘Log file name’ – Denial of Service (PoC)
Axessh 4.2 is vulnerable to a denial of service attack when a maliciously crafted string is supplied as the 'Log file name' parameter. This causes the application to crash when the 'OK' button is clicked.
Mitigation:
Users should avoid supplying untrusted input to the 'Log file name' parameter.