CVE-2018-25296
MEDIUMP10 Central Management Software 1.4.13 Denial of Service
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25296. PoCs published by Gionathan Reale.
AI-analyzed exploit summary This Python script generates a buffer overflow payload (2000 'A' characters) to trigger a Denial of Service (DoS) in Central Management Software v1.4.13 by pasting the payload into the 'Password' field during login. The exploit is straightforward and relies on a classic stack-based overflow to crash the application.
Description
P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows local attackers to crash the application by submitting an oversized input string. Attackers can paste a 2000-byte payload into the password field and click login to trigger an application crash and denial of service.
Exploits (1)
This Python script generates a buffer overflow payload (2000 'A' characters) to trigger a Denial of Service (DoS) in Central Management Software v1.4.13 by pasting the payload into the 'Password' field during login. The exploit is straightforward and relies on a classic stack-based overflow to crash the application.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H