Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libwsman1Upgrade openwsman-python3Upgrade openwsman-clientUpgrade libwsman-develUpgrade openwsman-server | May 4, 2022 | Mar 14, 2019 |
| Amazon Linux Ami 2 | — | Upgrade libwsman1Upgrade openwsman-serverUpgrade openwsman-clientUpgrade libwsman-develUpgrade openwsman-pythonUpgrade openwsman-rubyUpgrade openwsman-debuginfoUpgrade openwsman-perl | Oct 28, 2020 | Mar 14, 2019 |
| Centos_linux | — | Upgrade openwsman-python3-debuginfoUpgrade openwsman-pythonUpgrade libwsman1-debuginfoUpgrade openwsman-perlUpgrade libwsman1Upgrade libwsman-develUpgrade openwsman-debugsourceUpgrade openwsman-debuginfoUpgrade openwsman-client-debuginfoUpgrade rubygem-openwsman-debuginfoUpgrade openwsman-perl-debuginfoUpgrade openwsman-python3Upgrade openwsman-serverUpgrade openwsman-clientUpgrade openwsman-server-debuginfoUpgrade openwsman-ruby | Oct 1, 2020 | Mar 14, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openwsman-serverUpgrade openwsman-clientUpgrade openwsman-pythonUpgrade libwsman1 | Nov 19, 2019 | Mar 14, 2019 |
| Oracle_linux | — | Upgrade libwsman-develUpgrade openwsman-rubyUpgrade openwsman-serverUpgrade openwsman-clientUpgrade openwsman-pythonUpgrade openwsman-python3Upgrade libwsman1Upgrade openwsman-perl | Oct 7, 2020 | Mar 12, 2019 |
| Redhat_linux | — | Upgrade libwsman1-debuginfoUpgrade openwsman-clientUpgrade openwsman-debuginfoUpgrade openwsman-pythonUpgrade openwsman-serverUpgrade openwsman-python3-debuginfoUpgrade libwsman-develNo solution existsUpgrade openwsman-rubyUpgrade libwsman1Upgrade openwsman-server-debuginfoUpgrade openwsman-debugsourceUpgrade rubygem-openwsman-debuginfoUpgrade openwsman-client-debuginfoUpgrade openwsman-perlUpgrade openwsman-perl-debuginfoUpgrade openwsman-python3 | Oct 1, 2020 | Mar 14, 2019 |
| Rocky_linux | — | Upgrade openwsman-python3-debuginfoUpgrade libwsman1Upgrade libwsman-develUpgrade openwsman-client-debuginfoUpgrade openwsman-python3Upgrade openwsman-debuginfoUpgrade libwsman1-debuginfoUpgrade openwsman-debugsourceUpgrade openwsman-server-debuginfoUpgrade openwsman-serverUpgrade openwsman-client | Mar 12, 2024 | Mar 14, 2019 |
| Suse | — | Upgrade openwsman-serverUpgrade openwsman-clientUpgrade libwsman3Upgrade openwsman-rubyUpgrade openwsman-javaUpgrade openwsman-server-plugin-rubyUpgrade openwsman-ruby-docsUpgrade openwsman-pythonUpgrade python3-openwsmanUpgrade winrsUpgrade openwsman-perlUpgrade libwsman-develUpgrade libwsman1Upgrade libwsman_clientpp1Upgrade libwsman_clientpp-devel | Mar 19, 2019 | Mar 14, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 14, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub