PT-2023-27787 · Opennds+1 · Opennds+1

Standash

+1

·

Published

2023-11-17

·

Updated

2024-07-03

·

CVE-2023-41102

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenNDS versions prior to 10.1.3
Description An issue was discovered in the captive portal in OpenNDS, which has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory.
Recommendations For OpenNDS versions prior to 10.1.3, update OpenNDS to version 10.2.0 to resolve the issue. As a temporary workaround, consider restricting access to the captive portal to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Memory Leak

Weakness Enumeration

Related Identifiers

CVE-2023-41102

Affected Products

Debian
Opennds