PT-2025-29155 · Unknown · Callmanager

Pandatix

·

Published

2025-07-10

·

Updated

2025-08-14

·

CVE-2025-53634

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Chall-Manager versions prior to 0.1.4
Description: Chall-Manager, a platform-agnostic system for starting Challenges on Demand, is susceptible to a Denial of Service (DoS) attack via a slow loris attack against its HTTP Gateway. The gateway lacks a timeout setting, allowing an attacker to exhaust system resources. Exploitation does not require authentication or authorization. It is recommended to deploy Chall-Manager deep within the infrastructure to limit external access.
Recommendations: Update to version 0.1.4 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2026-00128
CVE-2025-53634
GHSA-GGMV-J932-Q89Q
GO-2025-3809
OPENSUSE-SU-2025:15405-1

Affected Products

Callmanager