CVE-2020-37185

7.5

Nsasoft · Nsauditor Backup Key Recovery

Backup Key Recovery 2.2.5 is susceptible to a buffer overflow vulnerability triggered by an overly long input in the registration name field, resulting in an application crash.

Executive summary

A buffer overflow vulnerability in Nsasoft Nsauditor Backup Key Recovery 2.2.5 allows an attacker to cause a denial of service by crashing the application.

Vulnerability

The software contains a classic buffer overflow (CWE-120) within the registration name input field. An unauthenticated attacker can trigger this condition by inputting a 1000-character payload, which causes the application to crash.

Business impact

Successful exploitation of this vulnerability results in a denial of service for the affected software. While the CVSS score of 7.5 indicates a high severity, the impact is localized to the availability of the specific application. This could disrupt administrative workflows that rely on the key recovery tool, potentially delaying critical system recovery tasks.

Remediation

Immediate Action: As there is no official patch currently available, users should restrict access to the application registration interface and exercise caution with untrusted input. Contact the vendor for potential updates or guidance regarding this vulnerability.

Proactive Monitoring: Monitor system logs for unexpected application termination events associated with the Backup Key Recovery process. Investigate any instances where the application crashes during registration or user input tasks.

Compensating Controls: Since this is a local application, ensure that only authorized personnel have access to the workstation where the software is installed. Endpoint protection solutions may assist in detecting or preventing memory corruption patterns associated with buffer overflows.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the Exploit Database (EDB-ID 47909).

Analyst recommendation

Given the availability of a public proof-of-concept, the risk of exploitation remains credible despite the lack of confirmed active attacks. Organizations should prioritize restricting access to the affected software and await further guidance or a security patch from Nsasoft. If the software is not mission-critical, consider deactivating or removing it until a resolution is provided.

Sources

Originally found and disclosed by Ismail Tasdelen, per the CVE Program record.