Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2f4-8vj5-m862

Опубликовано: 10 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 8.6

Описание

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions), Automation License Manager V6.2 (All versions < V6.2 Upd3). Affected applications do not properly validate certain fields in incoming network packets on port 4410/tcp. This could allow an unauthenticated remote attacker to cause an integer overflow and crash of the application. This denial of service condition could prevent legitimate users from using subsequent products that rely on the affected application for license verification.

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions), Automation License Manager V6.2 (All versions < V6.2 Upd3). Affected applications do not properly validate certain fields in incoming network packets on port 4410/tcp. This could allow an unauthenticated remote attacker to cause an integer overflow and crash of the application. This denial of service condition could prevent legitimate users from using subsequent products that rely on the affected application for license verification.

EPSS

Процентиль: 95%
0.1712
Средний

9.2 Critical

CVSS4

8.6 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 8.6
nvd
больше 1 года назад

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager V6.2 (All versions < V6.2 Upd3). Affected applications do not properly validate certain fields in incoming network packets on port 4410/tcp. This could allow an unauthenticated remote attacker to cause an integer overflow and crash of the application. This denial of service condition could prevent legitimate users from using subsequent products that rely on the affected application for license verification.

CVSS3: 8.6
fstec
больше 1 года назад

Уязвимость программного средства управления лицензиями Automation License Manager, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 95%
0.1712
Средний

9.2 Critical

CVSS4

8.6 High

CVSS3

Дефекты

CWE-190