CVE-2020-27523
11.11.2020, 15:15
Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_name, and operation_system parameter during the authentication process. This may crash the server and force Solstice-Pod to reboot, which leads to a denial of service.Enginsight
Vendor | Product | Version |
---|---|---|
mersive | solstice_pod_firmware | 𝑥 ≤ 5.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References