Lucene search

K
cveMitreCVE-2023-30082
HistoryJun 14, 2023 - 8:15 p.m.

CVE-2023-30082

2023-06-1420:15:09
CWE-1284
mitre
web.nvd.nist.gov
27
cve-2023-30082
denial of service
osticket
server crash
nvd
security vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

37.3%

A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a long password is entered, this procedure will consume all available CPU and memory.

Affected configurations

Nvd
Node
enhancesoftosticketMatch1.17.2
VendorProductVersionCPE
enhancesoftosticket1.17.2cpe:2.3:a:enhancesoft:osticket:1.17.2:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

37.3%

Related for CVE-2023-30082