Description
ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 contain a remote denial-of-service vulnerability. The device can be shut down or rebooted by an unauthenticated attacker through a single crafted HTTP GET request, allowing remote interruption of service availability.
Problem types
CWE-400 Uncontrolled Resource Consumption
Product status
7.0.3.4968
7.0.2.4954
6.5.2.4954
6.4.2.4681
6.3.2.4203
2.0.1.823
Timeline
| 2020-10-18: | ZSL-2020-5601 is publicly disclosed. |
Credits
Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5601.php
www.exploit-db.com/exploits/48951
cxsecurity.com/issue/WLB-2020100122
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5601.php
www.exploit-db.com/exploits/48951
packetstorm.news/files/id/159602
cxsecurity.com/issue/WLB-2020100122
exchange.xforce.ibmcloud.com/vulnerabilities/190031
www.request.com/
www.vulncheck.com/...serious-play-f3-media-server-remote-dos