Back to search
CVE-2020-27523
Published: Nov 11, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_name, and operation_system parameter during the authentication process. This may crash the server and force Solstice-Pod to reboot, which leads to a denial of service.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.youtube.com/watch?v=EGW_M1MqAG0
x_refsource_MISC
https://twitter.com/Kevin2600/status/1316261149403275264
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now