PT-2023-26355 · Opennds+1 · Opennds Captive Portal+1
Bluewavenet
·
Published
2023-11-17
·
Updated
2024-06-20
·
CVE-2023-38315
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenNDS Captive Portal versions prior to 10.1.2
Description
An issue in OpenNDS Captive Portal can be triggered with a crafted GET HTTP request that has a missing
client token query string parameter, resulting in a NULL pointer dereference in the try to authenticate function. This can cause OpenNDS to crash, leading to a Denial-of-Service condition.Recommendations
For OpenNDS Captive Portal versions prior to 10.1.2, update to version 10.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable API endpoint until the update is applied.
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Opennds Captive Portal