#VU92216 Infinite loop in DSE855 - CVE-2024-5949

 

#VU92216 Infinite loop in DSE855 - CVE-2024-5949

Published: June 18, 2024


Vulnerability identifier: #VU92216
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-5949
CWE-ID: CWE-835
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
DSE855
Software vendor:
Deep Sea Electronics

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the handling of multipart boundaries. A remote attacker on the local network can consume all available system resources and cause denial of service conditions.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links