PT-2024-31449 · Unknown · Uci Idol 2
Ludwig Stage
+1
·
Published
2024-08-21
·
Updated
2025-09-03
·
CVE-2024-45166
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UCI IDOL 2 versions through 2.12
Description
An issue was discovered in UCI IDOL 2 due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer. This issue makes UCI IDOL 2 vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. There is an access violation and EIP overwrite after five logins.
Recommendations
For UCI IDOL 2 versions through 2.12, consider disabling the login functionality until a patch is available to prevent potential Denial-of-Service (DoS) attacks and remote code execution. Restrict access to the system to minimize the risk of exploitation. Avoid using the system for critical operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
RCE
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uci Idol 2