vendor:
RAVPower
by:
Daniele Linguaglossa
7.5
CVSS
HIGH
Stack Disclosure
119
CWE
Product Name: RAVPower
Affected Version From: 2.000.056
Affected Version To: 2.000.056
Patch Exists: YES
Related CWE: CVE-2018-5319
CPE: a:ravpower:ravpower
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: OSX
2018
RAVPower – remote stack disclosure
A vulnerability in RAVPower devices allows an attacker to remotely disclose the stack memory of the device. This is achieved by sending a specially crafted HTTP request to the device, which contains a large number of '%0a' characters. This causes the stack memory to be returned in the response.
Mitigation:
The vendor has released a patch to address this vulnerability.