PT-2014-2691 · Dell+1 · Dell Powerconnect+1

Rijnard Van Tonder

·

Published

2014-01-20

·

Updated

2017-08-29

·

CVE-2013-3606

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Dell PowerConnect versions 1.2.1.3, 2.0.0.48, and 2.0.1.4
Description The issue concerns the login page in the GoAhead web server, which allows remote attackers to cause a denial of service, resulting in a device outage. This can be achieved by submitting a long username to the login page.
Recommendations For version 1.2.1.3, restrict access to the login page to prevent remote attackers from causing a denial of service. For version 2.0.0.48, limit the length of the username parameter to prevent exploitation. For version 2.0.1.4, consider disabling the login functionality until a fix is available to prevent device outages.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3606

Affected Products

Dell Powerconnect
Goahead Web Server