vendor:
NetVizor
by:
loneferret
7,5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: NetVizor
Affected Version From: Build Release 6.1
Affected Version To: Build Release 6.1
Patch Exists: NO
Related CWE: N/A
CPE: a:spytech_software:netvizor
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
NetVizor Client DoS
NetVizor is the latest in network monitoring software. It is possible to have the service crash by sending an overly large string. This will will overwrite EAX or ECX and the “Viewer” application will no longer be able to initiate a remote desktop connection nor will it be able to grab a screen capture.
Mitigation:
Ensure that the NetVizor “Viewer” application is not exposed to untrusted networks and that the port 5591 is not accessible from the internet.