vendor:
Disk Pulse Enterprise Server
by:
Ahmad Mahfouz
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Disk Pulse Enterprise Server
Affected Version From: v10.1.18
Affected Version To: v10.1.18
Patch Exists: YES
Related CWE: CVE-2017-15663
CPE: a:disk_pulse:disk_pulse_enterprise_server:10.1.18
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2017
Disk Pulse Enterprise Server v10.1.18 – DOS
Disk Pulse Enterprise Server v10.1.18 suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120.
Mitigation:
Ensure that the control port is not exposed to the public internet and that only trusted users have access to the port.