vendor:
Inetserv
by:
dmnt
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Inetserv
Affected Version From: 3.23
Affected Version To: 3.23
Patch Exists: NO
Related CWE:
CPE: a:avtronics:inetserv:3.23
Platforms Tested:
2011
Inetserv 3.23 POP3 DoS
This script exploits a Denial of Service vulnerability in Inetserv version 3.23. By sending a specially crafted buffer in the RETR or DELE command, an attacker can cause the server to crash or become unresponsive. The vulnerability allows an unauthenticated attacker to disrupt the normal operation of the POP3 service.
Mitigation:
Update to a patched version of Inetserv that addresses the vulnerability. Alternatively, restrict access to the POP3 service to trusted IP addresses or implement a firewall to block malicious requests.