Vulnerability Details CVE-2017-7458
The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-7458
-
cpe:2.3:a:ntop:ntopng:1.1
-
cpe:2.3:a:ntop:ntopng:1.2.0
-
cpe:2.3:a:ntop:ntopng:1.2.1
-
cpe:2.3:a:ntop:ntopng:2.0.151021
-
cpe:2.3:a:ntop:ntopng:2.4