Description
Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.
Problem types
Memory Allocation with Excessive Size Value
Product status
Credits
L0RD (borna nematzadeh)
References
www.exploit-db.com/exploits/45304 (ExploitDB-45304)
nordvpn.com/download/ (Product Reference)
www.vulncheck.com/...pn-denial-of-service-via-password-field (VulnCheck Advisory: Nord VPN 6.14.31 Denial of Service via Password Field)