PT-2022-7731 · Starwind · Starwind Iscsi Target
Published
2022-02-06
·
Updated
2022-09-01
·
CVE-2013-20004
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
StarWind iSCSI target versions prior to 6.0 build 2013-03-20
Description
A flaw was found in the StarWind iSCSI target, where the StarWind service does not limit client connections and allocates memory on each connection attempt. This could allow an attacker to create a denial of service state by attempting to connect to a non-existent target multiple times, resulting in a memory leak.
Recommendations
For versions prior to 6.0 build 2013-03-20, update to a version newer than 6.0 build 2013-03-20 to resolve the issue. As a temporary workaround, consider restricting access to the StarWind service to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Starwind Iscsi Target