Vulnerabilities > CVE-2021-27565 - Infinite Loop vulnerability in Hcc-Embedded Nichestack

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
hcc-embedded
CWE-835

Summary

The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loop and networking outage) via an unexpected valid HTTP request such as OPTIONS. This occurs because the HTTP request handler enters a miscoded wbs_loop() debugger hook.

Vulnerable Configurations

Part Description Count
Application
Hcc-Embedded
1