PT-2004-2586 · Wind River+1 · Vxworks Os+1

Published

2004-09-13

·

Updated

2017-07-11

·

CVE-2004-1680

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Pingtel Xpressa handset firmware 2.1.11.24
Description The issue allows remote authenticated users to cause a denial of service, potentially triggering a buffer overflow, by sending a long HTTP GET request. This can lead to a crash of the VxWorks OS.
Recommendations For firmware 2.1.11.24, consider restricting access to the application.cgi to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the length of HTTP GET requests to prevent potential buffer overflows.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1680

Affected Products

Pingtel Xpressa
Vxworks Os