PT-2017-14365 · Debut · Debut Embedded Http Server
Published
2017-11-09
·
Updated
2019-10-03
·
CVE-2017-16249
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Debut embedded http server (affected versions not specified)
Description
The issue allows for a remotely exploitable denial of service. A single malformed HTTP POST request can cause the server to hang, resulting in a delay of approximately 300 seconds before replying with an HTTP 500 error. During this time, the server is unable to process print jobs over the network and the web interface is inaccessible. An attacker can exploit this by continuously sending the malformed request, effectively blocking legitimate traffic.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debut Embedded Http Server