vendor:
Flexense HTTP Server
by:
Ege Balci
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: Flexense HTTP Server
Affected Version From: 10.6.24
Affected Version To: 10.6.24
Patch Exists: NO
Related CWE: CVE-2018-8065
CPE: a:flexense:flexense_http_server:10.6.24
Platforms Tested:
2018
Flexense HTTP Server 10.6.24 โ Buffer Overflow (DoS) (Metasploit)
This module triggers a Denial of Service vulnerability in the Flexense HTTP server. Vulnerability caused by a user mode write access memory violation and can be triggered with rapidly sending variety of HTTP requests with long HTTP header values. Multiple Flexense applications that are using Flexense HTTP server 10.6.24 and below vesions reportedly vulnerable.
Mitigation:
Upgrade to a version higher than 10.6.24