CVE-2020-9000
Summary
| CVE | CVE-2020-9000 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-01 11:15:00 UTC |
| Updated | 2021-09-09 11:35:00 UTC |
| Description | An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input Validation errors. This increases the size of the log file on the remote server until memory is exhausted, therefore consuming the maximum amount of resources (triggering a denial of service condition). |
Risk And Classification
Problem Types: CWE-400
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Iportalis | Iportalis Control Portal | 7.1.13.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Updates | Ultimum | MISC | www.ultimum.nl | |
| CVE Report August 2021 | MISC | websec.nl | |
| Websec Blog | MISC | websec.nl | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.