vendor:
Nord VPN
by:
L0RD (borna nematzadeh)
7.5
CVSS
HIGH
Denial of Service
119
CWE
Product Name: Nord VPN
Affected Version From: <= 6.14.31
Affected Version To: <= 6.14.31
Patch Exists: YES
Related CWE: N/A
CPE: a:nordvpn:nordvpn
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2018
Nord VPN <= 6.14.31 - Denial of Service (PoC)
A buffer overflow vulnerability exists in Nord VPN version <= 6.14.31 which allows an attacker to cause a denial of service condition by running a python exploit code and copying the content of the generated file into the password field of the Nord VPN application.
Mitigation:
Upgrade to the latest version of Nord VPN to mitigate this vulnerability.