PT-2025-29155 · Unknown · Callmanager
Pandatix
·
Published
2025-07-10
·
Updated
2025-08-14
·
CVE-2025-53634
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Chall-Manager versions prior to 0.1.4
Description:
Chall-Manager, a platform-agnostic system for starting Challenges on Demand, is susceptible to a Denial of Service (DoS) attack via a slow loris attack against its HTTP Gateway. The gateway lacks a timeout setting, allowing an attacker to exhaust system resources. Exploitation does not require authentication or authorization. It is recommended to deploy Chall-Manager deep within the infrastructure to limit external access.
Recommendations:
Update to version 0.1.4 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Callmanager