A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of service state by trying to connect a non-existent target multiple times. This affects iSCSI SAN (Windows Native) Version 6.0, build 2013-01-16.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://www.starwindsoftware.com/security/sw-20130215-0001/ | vendor advisory |