Description
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted HTTP request.
Affected products
- atvise / webmi2ads2.0.1
- atvise / webmi2ads1.0 – 1.0
- atvise / webmi2ads2.0 – 2.0