7.5
CVSSv3

CVE-2023-38313

Published: 17/11/2023 Updated: 23/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in OpenNDS Captive Portal prior to 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issue results in crashing openNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the BinAuth option is set.

Vulnerable Product Search on Vulmon Subscribe to Product

opennds captive portal

Vendor Advisories

Debian Bug report logs - #1059451 opennds: CVE-2023-38313 CVE-2023-38314 CVE-2023-38315 CVE-2023-38316 CVE-2023-38320 CVE-2023-38322 CVE-2023-38324 Package: src:opennds; Maintainer for src:opennds is Debian Edu Packaging Team <debian-edu-pkg-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianor ...