Lucene search

K
cvelist@huntrdevCVELIST:CVE-2022-1728
HistoryMay 16, 2022 - 2:55 p.m.

CVE-2022-1728 Allowing long password leads to denial of service in polonel/trudesk in polonel/trudesk

2022-05-1614:55:13
CWE-190
@huntrdev
www.cve.org
5
vulnerability
long password
dos
polonel/trudesk
github repository
ddos attack
genuine users

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

EPSS

0.001

Percentile

31.9%

Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

CNA Affected

[
  {
    "product": "polonel/trudesk",
    "vendor": "polonel",
    "versions": [
      {
        "lessThan": "1.2.2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

EPSS

0.001

Percentile

31.9%

Related for CVELIST:CVE-2022-1728