Vulnerabilities > CVE-2021-27565 - Infinite Loop vulnerability in Hcc-Embedded Nichestack 3.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
hcc-embedded
CWE-835

Summary

The web server in InterNiche NicheStack through 4.0.1 allows remote attackers to cause a denial of service (infinite loop and networking outage) via an unexpected valid HTTP request such as OPTIONS. This occurs because the HTTP request handler enters a miscoded wbs_loop() debugger hook.

Vulnerable Configurations

Part Description Count
Application
Hcc-Embedded
1