PT-2019-9940 · Teltonika · Teltonika Rtu950
Published
2019-06-19
·
Updated
2019-06-21
·
CVE-2018-19878
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Teltonika RTU950 version R 31.04.89
Description
The issue allows a user to login without limitation, causing the application to store sessions in memory for every successful login request. This can lead to increased memory use and consumption of free space.
Recommendations
For Teltonika RTU950 version R 31.04.89, consider implementing a mechanism to limit the number of concurrent logins or to automatically log out inactive sessions to prevent excessive memory use. As a temporary workaround, restrict the ability for users to re-login without logging out to minimize the risk of exploitation.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teltonika Rtu950