7.5
CVSSv3

CVE-2023-38322

Published: 17/11/2023 Updated: 23/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the BinAuth option is set.

Vulnerable Product Search on Vulmon Subscribe to Product

opennds captive portal

Vendor Advisories

Debian Bug report logs - #1059451 opennds: CVE-2023-38313 CVE-2023-38314 CVE-2023-38315 CVE-2023-38316 CVE-2023-38320 CVE-2023-38322 CVE-2023-38324 Package: src:opennds; Maintainer for src:opennds is Debian Edu Packaging Team <debian-edu-pkg-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianor ...