CVE-2024-49705 affects SoftCOM iKSORIS's Internet Starter module, making it vulnerable to client-side Denial of Service (DoS) attacks. An attacker can trick a user into accessing a URL with a malformed 'd' parameter or selecting an unimplemented language, causing the server to return errors and reject subsequent requests until the session expires or cookies are cleared. This vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and resulting in high availability impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 79.0CPE matchmatch criteria | cpe:2.3:a:softcom.wroc:iksoris:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.