vendor:
SpotAuditor
by:
ZwX
5.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name: SpotAuditor
Affected Version From: 5.3.2002
Affected Version To: 5.3.2002
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7
2019
SpotAuditor 5.3.2 – ‘Base64’ Denial Of Service (PoC)
This exploit allows an attacker to create a file with a long string of characters, causing SpotAuditor to crash when attempting to decrypt the characters. The exploit is performed by running a Python script that creates a file with a long string of characters, which is then copied and pasted into the 'Base64 Encrypted Password' field in SpotAuditor. This causes the software to crash.
Mitigation:
The vendor should release a patch or update to fix the vulnerability. In the meantime, users can avoid the exploit by not copying and pasting long strings of characters into the 'Base64 Encrypted Password' field.