CVE-2020-15473: Critical severity ntop nDPI vulnerability
Published Jul 1, 2020
·Updated
In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpisearchopenvpn in lib/protocols/openvpn.c.
Affected Software
1 affected component
ntop nDPI<=3.2
Remediation
Event History
Jul 1, 2020
CVE Published
via MITRE·10:54 AM
Data Sourced
via MITRE·10:54 AM
Description
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-15473?
CVE-2020-15473 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2020-15473?
To fix CVE-2020-15473, you should update nDPI to the latest version that exceeds 3.2.
3
What is the impact of CVE-2020-15473?
The impact of CVE-2020-15473 is a potential heap-based buffer over-read, which could lead to unintended memory access.
4
Which versions of nDPI are affected by CVE-2020-15473?
CVE-2020-15473 affects nDPI versions up to and including 3.2.
5
Is CVE-2020-15473 specific to any protocols?
Yes, CVE-2020-15473 specifically affects the OpenVPN dissector within the nDPI framework.