PT-2026-83270 · Planet · Gs-4210-16P2S
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PLANET GS-4210-16P2S versions prior to 3.441b260626
Description
A pre-authentication memory corruption issue exists in the web management interface. The
readHttpParam() function copies an oversized HTTP query string without ensuring NUL termination, which allows the parse query string() function to process attacker-controlled data into a fixed-size stack buffer. An unauthenticated remote attacker can send an oversized GET request to the 'dispatcher.cgi' endpoint to cause a denial of service of the web management interface or potentially trigger memory corruption.Recommendations
Update PLANET GS-4210-16P2S to version 3.441b260626 or later.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gs-4210-16P2S