Description
This module triggers a Denial of Service vulnerability in the Flexense HTTP server. Vulnerability caused by a user mode write access memory violation and can be triggered with rapidly sending variety of HTTP requests with long HTTP header values.
Multiple Flexense applications that are using Flexense HTTP server 10.6.24 and below versions reportedly vulnerable.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/dos/http/flexense/http_server_dosmsf undefined(http_server_dos) > show actions ...actions...msf undefined(http_server_dos) > set ACTION < action-name >msf undefined(http_server_dos) > show options ...show and set options...msf undefined(http_server_dos) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub