CVE-2018-15173
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/08/2018
Last modified:
27/08/2020
Description
Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:nmap:nmap:*:*:*:*:*:*:*:* | 7.70 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://code610.blogspot.com/2018/07/crashing-nmap-760.html
- http://code610.blogspot.com/2018/07/crashing-nmap-770.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00067.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00073.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00075.html
- https://security.netapp.com/advisory/ntap-20200827-0004/