Nsasoft SpotAuditor
cpe:2.3:a:nsauditor:spotauditor:*:*:*:*:*:*:*
- <= 3.6.7
A local buffer overflow vulnerability has been identified in SpotAuditor version 3.6.7, specifically within the Base64 Password Decoder component. This vulnerability allows attackers to cause a denial-of-service condition by supplying an oversized Base64 string through the decoder interface, which crashes the application.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to crash.
To reproduce this vulnerability, first run SpotAuditor 3.6.7. Then, navigate to the 'Tools' menu and select 'Base64 Password Decoder'. Paste an oversized Base64 string into the 'Base64 Encrypted Password' textbox and click the 'Decrypt' button. The application will crash, demonstrating the denial-of-service condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.