CVE-2019-25340
7.5Nsasoft · SpotAuditor
SpotAuditor 5.3.2 is vulnerable to a stack-based buffer overflow in its Base64 decryption feature, allowing an attacker to cause a denial of service via a malformed input string.
Executive summary
A stack-based buffer overflow in Nsasoft SpotAuditor 5.3.2 allows a local attacker to trigger an application crash, resulting in a denial of service.
Vulnerability
The application is susceptible to a stack-based buffer overflow (CWE-121) within the Base64 decryption component. By providing an oversized buffer of 2000 characters into the Base64 Encrypted Password field, an unauthenticated attacker can crash the application.
Business impact
Successful exploitation results in a denial of service, rendering the auditing tool unavailable for security personnel. While the CVSS score of 7.5 indicates a high severity, the impact is limited to the availability of the application itself rather than broader system compromise. This disruption can hinder incident response or security audit workflows, necessitating prompt attention.
Remediation
Immediate Action: As no official patch is currently available, users should restrict access to the application and ensure that only trusted personnel can interact with the interface.
Proactive Monitoring: Security teams should monitor system logs for unusual application termination events or crashes associated with the SpotAuditor process.
Compensating Controls: Implement endpoint security controls to monitor and block unauthorized or malformed input strings from being passed to sensitive application fields.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exploit is available via the Exploit Database (EDB-ID: 47719).
Analyst recommendation
Given the availability of a public proof-of-concept and the ease of exploitation, organizations utilizing SpotAuditor 5.3.2 must treat this vulnerability with urgency. If the software is not critical to daily operations, consider decommissioning or restricting its use until the vendor provides a formal security update to address the overflow condition.
Sources
Originally found and disclosed by ZwX, per the CVE Program record.
- ExploitDB-47719 Exploit / PoC
- Vendor Homepage
- VulnCheck Advisory: SpotAuditor 5.3.2 - 'Base64' Denial Of Service Third-party advisory