vendor:
Hardware Software Inventory
by:
Enes Özeser
7.8
CVSS
HIGH
Denial of Service
119
CWE
Product Name: Hardware Software Inventory
Affected Version From: 1.6.4.0
Affected Version To: 1.6.4.0
Patch Exists: YES
Related CWE: N/A
CPE: a:nsasoft:hardware_software_inventory:1.6.4.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2021
Nsasoft Hardware Software Inventory 1.6.4.0 – ‘multiple’ Denial of Service (PoC)
This vulnerability allows remote attackers to cause a denial of service (application crash) via a crafted input. An attacker must first obtain the target system, then send a malicious input to the vulnerable application in order to execute the attack. The specific flaw exists within the handling of the registration code. The issue lies in the lack of proper validation of user-supplied data, which can result in a stack-based buffer overflow. An attacker can leverage this vulnerability to execute arbitrary code in the context of the application.
Mitigation:
Upgrade to version 1.6.4.1 or later, as it has been reported to fix this vulnerability.