Skip to main content

Failure to Handle Incomplete Element

CVE-2020-10280

Severity High
Score 7.5/10

Summary

The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, effectively blocking the access to the dashboard.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-239 - Failure to Handle Incomplete Element

The software does not properly handle when a particular element is not completely specified.

References

Advisory Timeline

  • Published