vendor:
Smart VPN
by:
0xB9
7.5
CVSS
HIGH
Denial of Service
119
CWE
Product Name: Smart VPN
Affected Version From: 1.1.3.0
Affected Version To: 1.1.3.0
Patch Exists: YES
Related CWE: N/A
CPE: a:smart_vpn:smart_vpn:1.1.3.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2018
Smart VPN 1.1.3.0 – Denial of Service (PoC)
A buffer overflow vulnerability exists in Smart VPN 1.1.3.0, which can be exploited by a malicious user to cause a denial of service. The vulnerability is caused due to a boundary error when handling user-supplied input, which can be exploited to cause a stack-based buffer overflow by sending a specially crafted payload of 2100 bytes to the top right search bar. This can allow an attacker to crash the application.
Mitigation:
Upgrade to the latest version of Smart VPN 1.1.3.0 or apply the appropriate patch.