vendor:
Nsauditor
by:
Ismael Nava
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Nsauditor
Affected Version From: 3.2.2.0
Affected Version To: 3.2.2.0
Patch Exists: NO
Related CWE: N/A
CPE: a:nsauditor:nsauditor
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Home x64
2021
Nsauditor 3.2.2.0 – ‘Event Description’ Denial of Service (PoC)
Nsauditor 3.2.2.0 is vulnerable to a denial of service attack when a malicious user sends a large amount of data to the 'Event Description' field. This can be exploited by a remote attacker to crash the application.
Mitigation:
Ensure that the application is configured to limit the size of data that can be sent to the 'Event Description' field.