vendor:
cFos Personal Net
by:
N/A
7,5
CVSS
HIGH
Remote Heap Memory Corruption Denial of Service
119
CWE
Product Name: cFos Personal Net
Affected Version From: 3.09
Affected Version To: 3.09
Patch Exists: YES
Related CWE: N/A
CPE: a:cfos_software_gmbh:cfos_personal_net:3.09
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
cFos Personal Net v3.09 Remote Heap Memory Corruption Denial of Service
cFos Personal Net web server is vulnerable to a remote denial of service issue when processing multiple malformed POST requests in less than 3000ms. The issue occurs when the application fails to handle the data sent in the POST requests in a single socket connection causing heap memory corruption which results in a crash of the HTTP service.
Mitigation:
Upgrade to the latest version of cFos Personal Net web server.