Denial of Service Vulnerability in Axessh by LabF
CVE-2019-25590
6.9MEDIUM
What is CVE-2019-25590?
Axessh version 4.2 has a vulnerability that allows local attackers to cause a denial of service. By manipulating the logging configuration, attackers can input an excessively long string into the log file name field, specifically a buffer of 500 characters or more. This action can lead to the application crashing when a telnet connection is attempted, making services temporarily unavailable until resolved. It is essential for users of Axessh to be aware of this vulnerability and take appropriate measures to mitigate risks.
Affected Version(s)
Axessh 4.2
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Victor Mondragón
