vendor:
Cyclope Internet Filtering Proxy
by:
loneferret
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Cyclope Internet Filtering Proxy
Affected Version From: 4
Affected Version To: 4
Patch Exists: NO
Related CWE: N/A
CPE: a:cyclope_series:cyclope_internet_filtering_proxy
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 Professional / Windows Server 2008 R2 Standard
2011
Cyclope Internet Filtering Proxy 4.0 – CEPMServer.exe DoS (Poc)
The CEPMServer service is vulnerable to a denial of service attack when an abnormally large string is sent to it. This causes the service to crash, preventing it from logging user and computer names. The attack does not stop the filtering, but it does require a complete re-installation of Cyclope to restore the logging feature.
Mitigation:
Ensure that the CEPMServer service is not exposed to the public internet, and that only trusted users have access to it.