CVE-2020-37191
7.5Top Password Software · Dialup Password Recovery
A buffer overflow vulnerability in Dialup Password Recovery 1.30 allows local attackers to cause a denial of service by injecting a 5000-character payload into specific input fields.
Executive summary
A buffer overflow vulnerability in Top Password Software Dialup Password Recovery 1.30 allows local attackers to crash the application, resulting in a denial of service.
Vulnerability
The application is susceptible to a classic buffer overflow (CWE-120) when processing input in the User Name and Registration Code fields. An unauthenticated local attacker can trigger this condition by providing an excessively long string, leading to an application crash.
Business impact
Successful exploitation of this vulnerability results in the immediate termination of the Dialup Password Recovery service. While the impact is limited to a denial of service, it disrupts the functionality of the software, which may be critical for password management workflows. The CVSS score of 7.5 reflects the potential for service disruption, even though the attack vector requires local access.
Remediation
Immediate Action: Users should discontinue use of version 1.30 and check the vendor website for available updates or alternative solutions, as this version is known to be vulnerable.
Proactive Monitoring: Security teams should monitor system logs for application crashes or unexpected service terminations associated with the Dialup Password Recovery process.
Compensating Controls: Since this is a local application, ensure that access to the host machine is restricted to authorized personnel only to prevent unauthorized input of malicious payloads.
Exploitation status
Public Exploit Available: Yes, a proof of concept is available via ExploitDB (EDB-ID: 47907).
Analyst recommendation
The vulnerability presents a clear risk of service disruption. Organizations currently utilizing this software should verify if a patched version is available from Top Password Software. If no patch is provided, consider migrating to more secure, actively maintained password recovery alternatives to eliminate this exposure.
Sources
Originally found and disclosed by Antonio de la Piedra, per the CVE Program record.
- ExploitDB-47907 Exploit / PoC
- Vendor Homepage
- VulnCheck Advisory: Top Password Software Dialup Password Recovery 1.30 - Denial of Service Third-party advisory