Lucene search

K
cveVulDBCVE-2024-1195
HistoryFeb 02, 2024 - 10:15 p.m.

CVE-2024-1195

2024-02-0222:15:25
CWE-404
VulDB
web.nvd.nist.gov
20
vulnerability
itop vpn
denial of service
critical
security
nvd
cve-2024-1195

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.6

Confidence

High

EPSS

0

Percentile

5.1%

A vulnerability classified as critical was found in iTop VPN up to 4.0.0.1. Affected by this vulnerability is an unknown functionality in the library ITopVpnCallbackProcess.sys of the component IOCTL Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The identifier VDB-252685 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected configurations

Nvd
Vulners
Node
iobititop_vpnRange4.0.0.1
VendorProductVersionCPE
iobititop_vpn*cpe:2.3:a:iobit:itop_vpn:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "iTop",
    "product": "VPN",
    "versions": [
      {
        "version": "4.0.0.0",
        "status": "affected"
      },
      {
        "version": "4.0.0.1",
        "status": "affected"
      }
    ],
    "modules": [
      "IOCTL Handler"
    ]
  }
]

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.6

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2024-1195