PT-2023-26354 · Unknown+1 · Opennds Captive Portal+1

Bluewavenet

·

Published

2023-11-17

·

Updated

2024-06-20

·

CVE-2023-38314

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenNDS Captive Portal versions prior to 10.1.2 OpenNDS Captive Portal version 10.1.2 is not affected as the issue is fixed in version 10.1.3.
Description An issue was discovered in OpenNDS Captive Portal that has a NULL pointer dereference in the preauthenticated() function. This can be triggered with a crafted GET HTTP request with a missing redirect query string parameter. Triggering this issue results in crashing OpenNDS, leading to a Denial-of-Service condition.
Recommendations For OpenNDS Captive Portal versions prior to 10.1.2, update to version 10.1.3 to resolve the issue. As a temporary workaround, consider restricting access to the preauthenticated() function until a patch is available. Avoid using the redirect query string parameter in the affected API endpoint until the issue is resolved.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-38314

Affected Products

Debian
Opennds Captive Portal