PT-2017-14365 · Debut · Debut Embedded Http Server

Published

2017-11-09

·

Updated

2019-10-03

·

CVE-2017-16249

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Debut embedded http server (affected versions not specified)
Description The issue allows for a remotely exploitable denial of service. A single malformed HTTP POST request can cause the server to hang, resulting in a delay of approximately 300 seconds before replying with an HTTP 500 error. During this time, the server is unable to process print jobs over the network and the web interface is inaccessible. An attacker can exploit this by continuously sending the malformed request, effectively blocking legitimate traffic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-16249

Affected Products

Debut Embedded Http Server