PT-2022-17338 · Unknown · Freetakserver
Securitybits-Io
·
Published
2022-03-10
·
Updated
2023-08-08
·
CVE-2022-25508
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeTAKServer versions 1.9.8 through 1.9.8.4
Description
An access control issue in the component /ManageRoute/postRoute of FreeTAKServer allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. The issue affects the API endpoint "/ManageRoute/postRoute" and can be exploited by manipulating the route creation process.
Recommendations
For FreeTAKServer versions 1.9.8 through 1.9.8.4, update to version 1.9.8.5 to resolve the issue.
As a temporary workaround, consider restricting access to the /ManageRoute/postRoute endpoint to prevent unauthenticated attackers from exploiting the issue.
Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freetakserver