Vulnerabilities (CVE)

Filtered by vendor Dietpi-dashboard Project
Filtered by product Dietpi-dashboard
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-38505 1 Dietpi-dashboard Project 1 Dietpi-dashboard 2024-11-21 N/A 7.5 HIGH
DietPi-Dashboard is a web dashboard for the operating system DietPi. The dashboard only allows for one TLS handshake to be in process at a given moment. Once a TCP connection is established in HTTPS mode, it will assume that it should be waiting for a handshake, and will stay this way indefinitely until a handshake starts or some error occurs. In version 0.6.1, this can be exploited by simply not starting the handshake, preventing any other TLS handshakes from getting through. An attacker can lo ...

Show More