NA
CVSSv3

CVE-2024-49705

CVSSv4: 5.3 | CVSSv3: NA | CVSSv2: NA | VMScore: 630 | EPSS: 0.00055 | KEV: Not Included
Published: 14/04/2025 Updated: 15/04/2025

Vulnerability Summary

Client-Side Denial of Service in SoftCOM iKSORIS Internet Starter Module

Internet Starter, a module within the SoftCOM iKSORIS system, has a client-side Denial of Service (DoS) vulnerability. An attacker can cause disruption by tricking a user into using a URL with a specific parameter set to an unhandled value. When this occurs, the server returns an error message, and subsequent requests are not accepted. Because the problematic parameter is part of a session cookie, the issue continues until the session expires or the user manually deletes cookies. Users attempting to change the platform language to an unsupported option may experience a similar effect. SoftCOM addressed this vulnerability in version 79.0, providing a fix for the potential DoS attack.

Vulnerable Product Search on Vulmon Subscribe to Product

softcom iksoris