Junglewise Threat Intelligence

CVE-2019-25434: Nsasoft SpotAuditor stack-based buffer overflow in registration field

CVE-2019-25434 · Severity: high · CVSS 7.5 · Published 2026-02-20

Vendors: Nsasoft.

Executive brief

SpotAuditor, a tool used for recovering passwords and auditing network security, is vulnerable to a flaw that can cause the software to crash. By entering an excessively long name during the product registration process, an attacker can force the application to shut down unexpectedly. This results in a denial of service, preventing legitimate users from using the software for security auditing tasks.

Technical details

A stack-based buffer overflow (CWE-121) exists in Nsasoft SpotAuditor version 5.3.1.0 and potentially earlier versions. The vulnerability is located in the registration name input field, which fails to properly validate the length of user-supplied strings. An attacker can trigger an unhandled exception and crash the application by inputting a string of 5,000 bytes or more (e.g., a long sequence of 'A' characters). While some sources categorize the attack vector as network-based, the exploit typically requires local interaction with the application's registration interface. Successful exploitation results in a complete loss of availability for the application.

Affected products

  • Nsasoft (Nsauditor) SpotAuditor 5.3.1.0 and earlier

Timeline

  • 2019-10-14: disclosed: Initial exploit code published to Exploit-DB
  • 2026-02-20: advisory: CVE published and NVD entry created

References

Related threats