CVE-2018-25368

🟡 Monitoruj

W Nord VPN 6.14.31 występuje luka, która pozwala na zdalne zablokowanie aplikacji przez długie hasło.

CVSS
7.5
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)

Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-05-25 15:16:19 UTC
Ostatnia modyfikacja (NVD)2026-10-06 22:10:00 UTC
Referencje