PT-2017-14143 · Flexense · Sysgauge Server

Ahmad Mahfouz

·

Published

2017-12-28

·

Updated

2018-04-13

·

CVE-2017-15667

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Flexense SysGauge Server version 3.6.18
Description The issue concerns a denial of service in the Control Protocol of Flexense SysGauge Server. This can be triggered by sending a crafted SERVER GET INFO packet to the control port 9221.
Recommendations For Flexense SysGauge Server version 3.6.18, consider restricting access to control port 9221 to minimize the risk of exploitation. As a temporary workaround, limit the handling of SERVER GET INFO packets until a patch is available.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15667

Affected Products

Sysgauge Server