LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2019-25590

Published
CVSS6.2
Severitymedium
WeaknessCWE-1282
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Axessh 4.2 contains a denial of service vulnerability in the logging configuration that allows local attackers to crash the application by supplying an excessively long string in the log file name field. Attackers can enable session logging, paste a buffer of 500 or more characters into the log file name parameter, and trigger a crash when establishing a telnet connection.

References

← Back to the CVE Tracker

Our coverage of CVE-2019-25590

No stories yet. This page updates automatically when we publish reporting that references CVE-2019-25590.