ZeroHour

CVE-2018-19878

CVSS 3.0
6.5 medium
EPSS
1%p66
Published
()
Modified
Description

An issue was discovered on Teltonika RTU950 R_31.04.89 devices. The application allows a user to login without limitation. For every successful login request, the application saves a session. A user can re-login without logging out, causing the application to store the session in memory. Exploitation of this vulnerability will increase memory use and consume free space.

Vendors
teltonika
Products
rut950 firmware
Weakness
CWE-416
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.