MEDIUM
ObserverIP Scan Tool 1.4.0.1 Denial of Service via IP Field
Published Apr 26, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.12%
Description
ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the IP input field. Attackers can paste a 2000-byte buffer of repeated characters into the IP field and trigger a search operation to cause an application crash.
Affected products
- Vendor n/a Product ObserverIP Scan Tool Defaultn/a
- Version 1.4.0.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | ObserverIP Scan Tool | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-21815 Advisory
- https://p10.secure.hostingprod.com/@site.ambientweatherstore.com/ssl/iptools/IPTools64bit.exe product
- https://www.ambientweather.com product
- https://www.exploit-db.com/exploits/45204 exploit
- https://www.vulncheck.com/advisories/observerip-scan-tool-denial-of-service-via-ip-field third-party-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 26, 2026
Updated Apr 27, 2026
Reserved Apr 26, 2026
Link CVE-2018-25295
CISA Vulnrichment
Updated Apr 27, 2026
ENISA EUVD
EUVD-2018-21815 Assigner VulnCheck
Published Apr 26, 2026
Updated Apr 27, 2026
Exploited since n/a
Link EUVD-2018-21815