Description
Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/48441 (ExploitDB-48441)
www.extremenetworks.com (Extreme Networks Product Homepage)
community.extremenetworks.com/...ngine_Hive_OS_Announcements (HiveOS Product Announcements)
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5566.php (Zero Science Lab Disclosure (ZSL-2020-5566))
advisories.ncsc.nl/2020/ncsc-2020-0367.html (NCSC Security Advisory)
exchange.xforce.ibmcloud.com/vulnerabilities/181649 (IBM X-Force Vulnerability Exchange)
packetstorm.news/files/id/157587 (Packet Storm Security Exploit Entry)
www.vulncheck.com/...nauthenticated-remote-denial-of-service (VulnCheck Advisory: Extreme Networks Aerohive HiveOS <=11.x 11.x Unauthenticated Remote Denial of Service)