CVE-2020-8859

HIGH

ELOG Electronic Logbook 3.1.4-283534d - DoS

Title source: llm
STIX 2.1

Description

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ELOG Electronic Logbook 3.1.4-283534d. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of HTTP parameters. A crafted request can trigger the dereference of a null pointer. An attacker can leverage this vulnerability to create a denial-of-service condition. Was ZDI-CAN-10115.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-20-252/
Vendor Advisory x_refsource_misc
https://elog.psi.ch/elogs/Forum/69114

Scores

CVSS v3 7.5
EPSS 0.0349
EPSS Percentile 87.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (1)
psi/electronic_logbook 3.1.4-283534d
Published Mar 23, 2020
Tracked Since Feb 18, 2026