#VU84006 NULL pointer dereference in openNDS - CVE-2023-38315
Published: December 8, 2023
openNDS
openNDS
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the try_to_authenticate() function. A remote attacker can send a crafted GET HTTP with a missing client token query string parameter and perform a denial of service (DoS) attack.