CVE-2020-37194
7.5Nsasoft · Nsauditor Backup Key Recovery
Nsasoft Nsauditor Backup Key Recovery 2.2.5 is vulnerable to a buffer overflow that results in a denial of service when processing an overly long registration key input.
Executive summary
A buffer overflow vulnerability in Nsasoft Nsauditor Backup Key Recovery version 2.2.5 allows an attacker to crash the application, leading to a denial of service.
Vulnerability
The software fails to perform adequate boundary checks on the registration key input field, allowing a local attacker to trigger a buffer overflow (CWE-120) by providing a 1000-character payload. This flaw requires no special authentication, as the registration interface is accessible to local users.
Business impact
Successful exploitation results in the immediate termination of the application, causing a denial of service for the backup recovery utility. While the CVSS score of 7.5 reflects a high severity, the impact is primarily restricted to service availability on the host machine. Organizations relying on this software for critical key recovery operations face potential operational disruption if the application is rendered unusable.
Remediation
Immediate Action: As no official patch is currently available from the vendor, users should restrict access to the application executable to only authorized personnel to prevent unauthorized interaction with the registration interface.
Proactive Monitoring: Review system event logs for unexpected application crashes or service termination events associated with the Backup Key Recovery process.
Compensating Controls: Implement endpoint security policies that prevent the execution of untrusted code or unauthorized modifications to application inputs on workstations where this software is installed.
Exploitation status
Public Exploit Available: Yes, a proof of concept is available via the Exploit Database (EDB-ID 47864).
Analyst recommendation
Given the availability of a functional proof of concept, the risk of exploitation is elevated. Because a vendor-supplied patch is not currently confirmed, administrators should prioritize limiting access to the software and monitoring for suspicious activity. If the software is not mission critical, consider decommissioning it until a secure version is released.
Sources
Originally found and disclosed by Ismail Tasdelen, per the CVE Program record.
- ExploitDB-47864 Exploit / PoC
- Vendor Homepage
- VulnCheck Advisory: Backup Key Recovery Recover Keys Crashed Hard Disk Drive 2.2.5 - 'Key' Denial of Service Third-party advisory