CVE-2023-38315: Null Pointer Dereference
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a trytoauthenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38315?
CVE-2023-38315 is a vulnerability in OpenNDS Captive Portal before version 10.1.2, where a crafted GET HTTP request can trigger a NULL pointer dereference, leading to a denial-of-service condition.
How severe is CVE-2023-38315?
CVE-2023-38315 has a severity rating of 7.5 out of 10, indicating a high severity vulnerability.
How can CVE-2023-38315 be exploited?
CVE-2023-38315 can be exploited by sending a crafted GET HTTP request with a missing client token query string parameter.
What is the affected software for CVE-2023-38315?
The affected software is OpenNDS Captive Portal before version 10.1.2.
Is there a fix available for CVE-2023-38315?
Yes, a fix is available in version 10.1.2 of OpenNDS Captive Portal.