Short Name |
APP:DISKPULSE-GETSERVERINFO-OF |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
APP |
Keywords |
DiskPulse Server 'GetServerInfo' Buffer Overflow Remote Code Execution Vulnerability |
Release Date |
2010/11/09 |
Update Number |
1812 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known remote code-execution vulnerability in DiskPulse Server. It is because it fails to properly bounds-check user-supplied data. Specifically, a buffer-overflow condition occurs when an overly long string is provided in the "GetServerInfo" request. An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts can cause denial-of-service conditions.
DiskPulse Server is prone to a remote code-execution vulnerability because it fails to properly bounds-check user-supplied data. An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition. DiskPulse Server 2.2.34 is vulnerable; other versions may also be affected.