vendor:
Kiwi Syslog Server
by:
Guillaume Kaddouch
7,5
CVSS
HIGH
Remote Denial of Service
400
CWE
Product Name: Kiwi Syslog Server
Affected Version From: 9.6.1.6
Affected Version To: 9.6.1.6
Patch Exists: NO
Related CWE: N/A
CPE: a:solarwinds:kiwi_syslog_server:9.6.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1 Family x64 (FR) and Windows 8.1 Pro x64
2017
Solarwinds Kiwi Syslog 9.6.1.6 – Remote Denial of Service (Type Mismatch)
A remote Denial of Service exists in Kiwi Syslog 9.6.1.6 in the TCP listener. Apparently any data sent to it make it crash because of a Type Mismatch error. The syslog TCP listener is disabled by default.
Mitigation:
Disable the TCP listener in the settings.