CVE-2020-9000

An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input Validation errors. This increases the size of the log file on the remote server until memory is exhausted, therefore consuming the maximum amount of resources (triggering a denial of service condition).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:iportalis:iportalis_control_portal:7.1.13.0:*:*:*:*:*:*:*

History

09 Sep 2021, 11:35

Type Values Removed Values Added
CWE CWE-400
References (MISC) https://websec.nl/blog/6127847280e759c7d31286d0/cve%20report%20august%202021/ - (MISC) https://websec.nl/blog/6127847280e759c7d31286d0/cve%20report%20august%202021/ - Third Party Advisory
References (MISC) https://websec.nl/blog/ - (MISC) https://websec.nl/blog/ - Third Party Advisory
CPE cpe:2.3:a:iportalis:iportalis_control_portal:7.1.13.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

02 Sep 2021, 13:15

Type Values Removed Values Added
References
  • {'url': 'https://www.ultimum.nl/updates/', 'name': 'https://www.ultimum.nl/updates/', 'tags': [], 'refsource': 'MISC'}

01 Sep 2021, 11:54

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-01 11:15

Updated : 2024-02-04 21:47


NVD link : CVE-2020-9000

Mitre link : CVE-2020-9000

CVE.ORG link : CVE-2020-9000


JSON object : View

Products Affected

iportalis

  • iportalis_control_portal
CWE
CWE-400

Uncontrolled Resource Consumption