PT-2020-12936 · Ntop · Ndpi

Anticomputer

+1

·

Published

2020-04-23

·

Updated

2020-05-06

·

CVE-2020-11940

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions nDPI versions 3.2 Stable and earlier
Description The issue allows a network-positioned attacker to exploit an out-of-bounds read in concat hash string in ssh.c by sending malformed SSH protocol messages on a network segment monitored by nDPI's library.
Recommendations For nDPI versions 3.2 Stable and earlier, consider restricting access to the ssh.c module to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the concat hash string function in the affected ssh.c file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11940

Affected Products

Ndpi