PT-2020-20600 · Signotec · Signotec Signopad-Api/Web
Published
2020-03-20
·
Updated
2020-03-24
·
CVE-2020-9345
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
signotec signoPAD-API/Web versions prior to 3.1.1
Description
The issue allows for a Denial of Service attack due to the application not limiting the number of opened WebSocket sockets. This can be exploited if a victim visits an attacker-controlled website.
Recommendations
For versions prior to 3.1.1, update to version 3.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the WebSocket API to minimize the risk of exploitation.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Signotec Signopad-Api/Web