CVE-2018-25368
HIGHNord VPN 6.14.31 Denial of Service via Password Field
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25368. PoCs published by L0RD.
AI-analyzed exploit summary This exploit generates a large buffer of 'A' characters (100,000 bytes) and writes it to a file. When pasted into the NordVPN password field, it triggers a denial-of-service condition, crashing the application. The PoC is functional but lacks sophistication.
Description
Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.
Exploits (1)
This exploit generates a large buffer of 'A' characters (100,000 bytes) and writes it to a file. When pasted into the NordVPN password field, it triggers a denial-of-service condition, crashing the application. The PoC is functional but lacks sophistication.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N