vendor:
NetAware
by:
Alejandra Sánchez
2.6
CVSS
LOW
Denial of Service
400
CWE
Product Name: NetAware
Affected Version From: 1.20
Affected Version To: 1.20
Patch Exists: NO
Related CWE: N/A
CPE: a:infiltration_systems:netaware:1.20
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2019
NetAware 1.20 – ‘Share Name’ Denial of Service (PoC)
NetAware 1.20 is vulnerable to a denial of service attack when a maliciously crafted 'Share Name' is entered into the 'Manage Shares' > 'Add a New Share...' dialog. This causes a crash of the application.
Mitigation:
Ensure that user input is properly validated and sanitized before being used.