vendor:
SpotAuditor
by:
ZwX
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: SpotAuditor
Affected Version From: 5.3.2002
Affected Version To: 5.3.2002
Patch Exists: NO
Related CWE:
CPE: a:nsauditor:spotauditor:5.3.2
Platforms Tested: Windows 7
2019
SpotAuditor 5.3.2 – ‘Key’ Denial of Service
The SpotAuditor 5.3.2 software is vulnerable to a denial of service attack when a specially crafted 'Key' value is provided. By supplying a large number of characters, the software crashes. This vulnerability allows an attacker to disrupt the normal functioning of the software.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability. Avoid providing a large number of characters in the 'Key' field to prevent the software from crashing.