PT-2023-26360 · Unknown+1 · Opennds Captive Portal+1

Bluewavenet

·

Publicado

2023-11-17

·

Atualizado

2024-06-20

·

CVE-2023-38322

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenNDS Captive Portal versions prior to 10.1.2
Description An issue in OpenNDS Captive Portal can be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header, resulting in a NULL pointer dereference. This can cause OpenNDS to crash, leading to a Denial-of-Service condition. The issue occurs during client authentication and can only be triggered when the BinAuth option is set.
Recommendations For OpenNDS Captive Portal versions prior to 10.1.2, update to version 10.1.3 or later to resolve the issue. As a temporary workaround, consider disabling the BinAuth option until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the User-Agent header in the affected API endpoint until the issue is resolved.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-38322

Produtos afetados

Debian
Opennds Captive Portal