PT-2023-26355 · Opennds+1 · Opennds Captive Portal+1

Bluewavenet

·

Published

2023-11-17

·

Updated

2024-06-20

·

CVE-2023-38315

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenNDS Captive Portal versions prior to 10.1.2
Description An issue in OpenNDS Captive Portal can be triggered with a crafted GET HTTP request that has a missing client token query string parameter, resulting in a NULL pointer dereference in the try to authenticate function. This can cause OpenNDS to crash, leading to a Denial-of-Service condition.
Recommendations For OpenNDS Captive Portal versions prior to 10.1.2, update to version 10.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable API endpoint until the update is applied.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-38315

Affected Products

Debian
Opennds Captive Portal