vendor:
DiskBoss Enterprise Server
by:
Ahmad Mahfouz
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: DiskBoss Enterprise Server
Affected Version From: 8.5.12
Affected Version To: 10.1.16
Patch Exists: YES
Related CWE: CVE-2017-15665
CPE: a:flexense:diskboss_enterprise_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2017
DiskBoss Enterprise Server 8.5.12 – Denial of Service
DiskBoss Enterprise Server 8.5.12 the Control Protocol suffers from a denial of service. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.
Mitigation:
Ensure that the control port is not exposed to the public internet and is only accessible from trusted networks.