Denial-of-Service Vulnerability in CoTURN Web Server by Cisco
CVE-2020-6062

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 February 2020

What is CVE-2020-6062?

A denial-of-service vulnerability exists in CoTURN 4.5.1.1 due to improper parsing of HTTP POST requests. An attacker can exploit this by crafting a specific POST request, which may lead to server instability and potential crashes. This issue highlights the need for vigilance in handling unexpected input to web servers to maintain service availability.

Affected Version(s)

CoTURN CoTURN 4.5.1.1

References

EPSS Score

8% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.