CVE-2020-27523 Information

Description

Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers x; p; c and s in the screen_key display_name browser_name and operation_system parameter during the authentication process. This may crash the server and force Solstice-Pod to reboot which leads to a denial of service.

Reference

https://documentation.mersive.com/content/topics/general-gen2i-pod-specs.htm https://tiger-team-1337.blogspot.com/2020/10/solstice-pod-critical-unauthenticated.html https://twitter.com/Kevin2600/status/1316261149403275264 https://www.youtube.com/watch?v=EGW_M1MqAG0

Share on: