PT-2014-2691 · Dell+1 · Dell Powerconnect+1
Rijnard Van Tonder
·
Publicado
2014-01-20
·
Atualizado
2017-08-29
·
CVE-2013-3606
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Dell PowerConnect versions 1.2.1.3, 2.0.0.48, and 2.0.1.4
Description
The issue concerns the login page in the GoAhead web server, which allows remote attackers to cause a denial of service, resulting in a device outage. This can be achieved by submitting a long
username to the login page.Recommendations
For version 1.2.1.3, restrict access to the login page to prevent remote attackers from causing a denial of service.
For version 2.0.0.48, limit the length of the
username parameter to prevent exploitation.
For version 2.0.1.4, consider disabling the login functionality until a fix is available to prevent device outages.Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dell Powerconnect
Goahead Web Server