vendor:
NetAware
by:
Alejandra Sánchez
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: NetAware
Affected Version From: 1.20
Affected Version To: 1.20
Patch Exists: NO
Related CWE: N/A
CPE: a:infiltration_systems:netaware
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2019
NetAware 1.20 – ‘Add Block’ Denial of Service (PoC)
NetAware 1.20 is vulnerable to a denial of service attack when a maliciously crafted string is pasted into the 'Add a website or keyword to be filtered...' field in the 'User Blocking' section of the 'Settings' menu. When the 'Remove' button is clicked, the application crashes.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.