Buffer Overflow Vulnerability in P10 Central Management Software by Ambient Weather
CVE-2018-25296
What is CVE-2018-25296?
The P10 Central Management Software version 1.4.13 is vulnerable to a buffer overflow in the login password field. This flaw allows local attackers to execute a Denial of Service (DoS) attack by submitting an excessively large input string, specifically a 2000-byte payload. When the payload is input into the password field and the user clicks login, it triggers the application to crash, resulting in service disruption. This vulnerability poses a significant risk to system stability and usability.
Affected Version(s)
Central Management Software 1.4.13
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
