CVE Database
/

CVE-2019-3833

Back to search

CVE-2019-3833

Published: Mar 14, 2019

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.0

7.5

HIGH

Description

Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.

VendorProductVersions

[UNKNOWN]

openwsman

affected
versions up to and including 2.6.9

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

References

107367
vdb-entry
x_refsource_BID
FEDORA-2019-348166f7fd
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-64b384de9b
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-af0cd1b8f7
vendor-advisory
x_refsource_FEDORA
openSUSE-SU-2019:1111
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1217
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now