Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LDefault status
unaffected
VC:00 (semver) before VC:07
affected
Default status
unaffected
VC:00 (semver) before VC:07
affected
Default status
unaffected
VC:00 (semver) before VC:07
affected
Default status
unaffected
VC:00 (semver) before VC:07
affected
Description
The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a crafted websocket message to trigger the issue without affecting the core functionality.
Problem types
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
VC:00 (semver) before VC:07
VC:00 (semver) before VC:07
VC:00 (semver) before VC:07
VC:00 (semver) before VC:07
Credits
D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube Security Research
References
seclists.org/fulldisclosure/2025/Oct/12
certvde.com/de/advisories/VDE-2025-072