AMPPS Encryption Passphrase Handler Vulnerability Could Lead to Remote Denial of Service
CVE-2024-1189
Key Information:
Badges
What is CVE-2024-1189?
A vulnerability exists within the AMPPS 2.7 platform that affects the Encryption Passphrase Handler, which can be exploited to cause a denial of service. This vulnerability can be triggered remotely, allowing attackers to disrupt service without needing physical access to the system. The issue has been made public, raising concerns about its exploitation potential. To mitigate risks associated with this vulnerability, users are strongly advised to upgrade to AMPPS version 4.0, which includes a complete code rewrite addressing this and other issues.
Affected Version(s)
AMPPS 2.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
CVSS V3.0
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
