Vulnerability Description
A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of service state by trying to connect a non-existent target multiple times. This affects iSCSI SAN (Windows Native) Version 6.0, build 2013-01-16.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Starwindsoftware | Iscsi San | < 6.0 |
Related Weaknesses (CWE)
References
- https://www.starwindsoftware.com/security/sw-20130215-0001/Vendor Advisory
- https://www.starwindsoftware.com/security/sw-20130215-0001/Vendor Advisory
FAQ
What is CVE-2013-20004?
CVE-2013-20004 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of service state by try...
How severe is CVE-2013-20004?
CVE-2013-20004 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2013-20004?
Check the references section above for vendor advisories and patch information. Affected products include: Starwindsoftware Iscsi San.