Improper Range Header Processing Vulnerability
CVE-2019-3721

4.3MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
25 April 2019

Summary

Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vulnerability. A remote unauthenticated attacker may send crafted requests with overlapping ranges to cause the application to compress each of the requested bytes, resulting in a crash due to excessive memory consumption and preventing users from accessing the system.

Affected Version(s)

Open Manage System Administrator 9.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell EMC would like to thank Murat Aydemir of Biznet Billisim A.S. for reporting this issue.
.