CVE-2018-25169
High
|8.7Exploit Available
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows attackers to crash the AMPPS service by overwhelming it with bad data sent to its default HTTP port. They can do this remotely by opening multiple connections, which can exhaust the server's resources and make it unavailable to legitimate users.
Technical Description
AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malformed data to the default HTTP port. Attackers can establish multiple socket connections and transmit invalid payloads to exhaust server resources and cause service unavailability.
CVSS Vector Analysis
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeChanged
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$4,579($1K-$5K)
Vendor Response
Grade APatched in 3 days
Quick Information
Published
Mar 6, 2026
about 1 month ago
Last Modified
Mar 9, 2026
30 days ago