CVE-2018-25295
ObserverIP Scan Tool 1.4.0.1 Denial of Service via IP Field
CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th
ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the IP input field. Attackers can paste a 2000-byte buffer of repeated characters into the IP field and trigger a search operation to cause an application crash.
| CWE | CWE-789 |
| Vendor | p10 |
| Product | observerip scan tool |
| Published | Apr 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for p10 observerip scan tool
Be the first to know when new medium vulnerabilities affecting p10 observerip scan tool are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
P10 / ObserverIP Scan Tool
1.4.0.1
References
exploit-db.com: https://www.exploit-db.com/exploits/45204 ambientweather.com: https://www.ambientweather.com p10.secure.hostingprod.com: https://p10.secure.hostingprod.com/@site.ambientweatherstore.com/ssl/iptools/IPTools64bit.exe vulncheck.com: https://www.vulncheck.com/advisories/observerip-scan-tool-denial-of-service-via-ip-field
Credits
Gionathan "John" Reale