CVE Published: 28/09/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: F-SecureUS |
Vendor: F-Secure |
Product: F-Secure Internet Gatekeeper Status : PUBLISHED
CVE-2021-33600 Description
A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username parameter. A successful exploitation could lead to a denial-of-service of the product.
Metrics
CVSS Version: 3.1 |
Base Score: 5.4 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N