Executive brief
Kron PAM, a solution used for managing and securing administrative access to sensitive systems, is vulnerable to a denial-of-service attack. An attacker can overwhelm the system's resources via HTTP requests, potentially making the management console unavailable to legitimate administrators. This could disrupt IT operations and prevent security teams from managing access during an incident.
Technical details
A resource exhaustion vulnerability (CWE-770) exists in Kron Technologies Kron PAM before version 3.7. The application fails to properly limit or throttle certain HTTP requests, allowing an authenticated user with low privileges to consume excessive system resources. This can be exploited over the network to trigger a Denial of Service (DoS) condition, impacting the availability of the PAM service. The issue is resolved in version 3.7.
Affected products
- Kron Technologies Kron PAM before 3.7
Timeline
- 2025-07-25: advisory: Initial publication by TR-CERT/USOM