CVE-2020-9345

MEDIUM

signotec signoPAD-API/Web < 3.1.1 - Denial of Service via Unlimited WebSocket Connections

Title source: llm
STIX 2.1

Description

An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the application doesn't limit the number of opened WebSocket sockets. If a victim visits an attacker-controlled website, this vulnerability can be exploited.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0092
EPSS Percentile 55.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-770
Status published
Products (1)
signotec/signopad-api\/web < 3.1.1
Published Mar 20, 2020
Tracked Since Feb 18, 2026