PT-2014-2691 · Dell+1 · Dell Powerconnect+1

Rijnard Van Tonder

·

Publicado

2014-01-20

·

Atualizado

2017-08-29

·

CVE-2013-3606

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Dell PowerConnect versions 1.2.1.3, 2.0.0.48, and 2.0.1.4
Description The issue concerns the login page in the GoAhead web server, which allows remote attackers to cause a denial of service, resulting in a device outage. This can be achieved by submitting a long username to the login page.
Recommendations For version 1.2.1.3, restrict access to the login page to prevent remote attackers from causing a denial of service. For version 2.0.0.48, limit the length of the username parameter to prevent exploitation. For version 2.0.1.4, consider disabling the login functionality until a fix is available to prevent device outages.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3606

Produtos afetados

Dell Powerconnect
Goahead Web Server