vendor:
SAPlpd
by:
Peter Baris
8,8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: SAPlpd
Affected Version From: 7.40
Affected Version To: 7.40
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2008 R2 x64, Windows 7 Pro x64
2016
SAPlpd 7.40 Denial of Service
The vulnerability exists in the Opcodes 03h and 04h of SAPlpd 7.40, which are vulnerable to bad characters 00h and 0ah. An attacker can send a payload of 800 A's to crash the SAPlpd 7.40.
Mitigation:
The user should update to the latest version of SAPlpd 7.40 and ensure that all patches are applied.