Out-of-bounds Read Vulnerability in nDPI by ntop
CVE-2020-11940

7.5HIGH

Key Information:

Vendor

Ntop

Status
Vendor
CVE Published:
23 April 2020

What is CVE-2020-11940?

nDPI, developed by ntop, is susceptible to an out-of-bounds read vulnerability located in the concat_hash_string function within the ssh.c file. This flaw allows a network-based attacker to exploit the library by sending crafted SSH protocol messages to a segment being monitored by nDPI. If successful, this vulnerability could lead to unforeseen behaviors or information disclosure, compromising the integrity and confidentiality of the monitored network traffic.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.