vendor:
Centova Cast
by:
DroidU
7.5
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: Centova Cast
Affected Version From: <=v3.2.12
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian 9, CentOS 7
2019
Centova Cast 3.2.12 – Denial of Service (PoC)
The Centova Cast becomes out of control and causes 100% CPU load on all cores. A bash script is used to exploit the vulnerability by sending a request to the API with a filename of /dev/zero, which causes the Centova Cast to become out of control and cause 100% CPU load on all cores.
Mitigation:
Upgrade to the latest version of Centova Cast, which is not vulnerable to this exploit.