vendor:
Infiltrator Network Security Scanner
by:
Gionathan 'John' Reale
7.8
CVSS
HIGH
Denial of Service
119
CWE
Product Name: Infiltrator Network Security Scanner
Affected Version From: 4.6
Affected Version To: 4.6
Patch Exists: YES
Related CWE: N/A
CPE: a:infiltration_systems:infiltrator_network_security_scanner
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 32-bit
2018
Infiltrator Network Security Scanner 4.6 – Denial of Service (PoC)
A buffer overflow vulnerability exists in Infiltrator Network Security Scanner 4.6, which could allow an attacker to cause a denial of service condition. An attacker can create a malicious file containing 6000 bytes of data and paste the contents of the file into the 'Scan Target' field. When the 'Scan' button is clicked, the application will crash.
Mitigation:
Upgrade to the latest version of Infiltrator Network Security Scanner.