vendor:
Nsauditor Network Security Auditor
by:
SajjadBnd
7.5
CVSS
HIGH
Denial of Service (DoS) Local
400
CWE
Product Name: Nsauditor Network Security Auditor
Affected Version From: 3.1.8.0
Affected Version To: 3.1.8.0
Patch Exists: YES
Related CWE: N/A
CPE: a:nsauditor:nsauditor_network_security_auditor
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 - Pro
2019
Nsauditor 3.1.8.0 – ‘Name’ Denial of Service (PoC)
Nsauditor Network Security Auditor is a powerful network security tool designed to scan networks and hosts for vulnerabilities, and to provide security alerts. A malicious user can create a file with a large number of characters and paste it into the 'Name' field of the 'Register -> Enter Registration Code' window, resulting in a denial of service.
Mitigation:
Ensure that the application is updated to the latest version and that all input is validated and sanitized.