PoC Index

CVE-2024-1184

MEDIUM 5.5EPSS 0.4%

A vulnerability was found in Nsasoft Network Sleuth 3.0.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-252674 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Eine problematische Schwachstelle wurde in Nsasoft Network Sleuth 3.0.0.0 ausgemacht. Hierbei geht es um eine nicht exakt ausgemachte Funktion der Komponente Registration Handler. Durch Manipulation mit unbekannten Daten kann eine denial of service-Schwachstelle ausgenutzt werden. Der Angriff muss lokal passieren. Der Exploit steht zur öffentlichen Verfügung.

CVSS v3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v3.1
3.3 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS v2.0
1.7 LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
EPSS
0.39% chance of exploitation in the next 30 days, 32th percentile
Published
2024-02-02
Updated
2024-08-29

Proof-of-concept exploits (1)

References

Related