Description
P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows local attackers to crash the application by submitting an oversized input string. Attackers can paste a 2000-byte payload into the password field and click login to trigger an application crash and denial of service.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Gionathan "John" Reale
References
www.exploit-db.com/exploits/45207 (ExploitDB-45207)
www.ambientweather.com (Official Product Homepage)
www.vulncheck.com/...l-management-software-denial-of-service (VulnCheck Advisory: P10 Central Management Software 1.4.13 Denial of Service)