Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-29238. PoCs published by Jai Kumar Sharma.
AI-analyzed exploit summary The exploit demonstrates an integer overflow vulnerability in the Nginx range filter module used by ExpressVPN Router version 1.0, allowing sensitive information leakage via a crafted HTTP request with malformed Range headers.
Description
An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.
Exploits (1)
The exploit demonstrates an integer overflow vulnerability in the Nginx range filter module used by ExpressVPN Router version 1.0, allowing sensitive information leakage via a crafted HTTP request with malformed Range headers.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N