CVE-2012-4435

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
22/10/2012
Last modified:
11/04/2025

Description

fwknop before 2.0.3 does not properly validate IP addresses, which allows remote authenticated users to cause a denial of service (server crash) via a long IP address.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cipherdyne:fwknop:*:*:*:*:*:*:*:* 2.0.2 (including)
cpe:2.3:a:cipherdyne:fwknop:2.0:*:*:*:*:*:*:*
cpe:2.3:a:cipherdyne:fwknop:2.0.1:*:*:*:*:*:*:*