7.5
CVSSv3

CVE-2016-10079

Published: 01/02/2017 Updated: 28/02/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

SAPlpd up to and including 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515.

Vulnerable Product Search on Vulmon Subscribe to Product

sap saplpd

Exploits

# Exploit Title: SAPlpd 740 Denial of Service # Date: 2016-12-28 # Exploit Author: Peter Baris # Exploit code: saptech-erpcomau/resources/saplpd_doszip # Version: 740 all patch levels (as a part of SAPGui 740) # Tested on: Windows Server 2008 R2 x64, Windows 7 Pro x64 import socket # Opcodes 03h and 04h are vulnerable to bad chara ...