vendor:
SitAware
by:
2u53
5.3
CVSS
MEDIUM
Denial of Service
20
CWE
Product Name: SitAware
Affected Version From: 6.4 SP2
Affected Version To: 6.4 SP2
Patch Exists: NO
Related CWE: CVE-2018-9115
CPE: //a:systematic:sitaware
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows Server 2012 R2
2018
SitAware NVG Denial of Service
Systematic's SitAware does not validate input from other sources suffenciently. Incoming information utilizing the for example the NVG interface. The following PoC will freeze the Situational Layer of SitAware, which means that the Situational Picture is no more updated. Unfortunately the user can not notice until he tries to work with the situational layer.
Mitigation:
Validate input from other sources suffenciently.