SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a malformed input file with 2000 repeated characters to trigger an application crash when pasted into the Base64 Encrypted Password field.

Project Subscriptions

Vendors Products
Nsasoft Subscribe
Nsauditor Spotauditor Subscribe
Spotauditor Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 20 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Nsasoft spotauditor
CPEs cpe:2.3:a:nsasoft:spotauditor:5.3.2:*:*:*:*:*:*:*
Vendors & Products Nsasoft spotauditor

Fri, 13 Feb 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Nsasoft
Nsasoft nsauditor Spotauditor
Vendors & Products Nsasoft
Nsasoft nsauditor Spotauditor

Fri, 13 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a malformed input file with 2000 repeated characters to trigger an application crash when pasted into the Base64 Encrypted Password field.
Title SpotAuditor 5.3.2 - 'Base64' Denial Of Service
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-13T17:59:14.954Z

Reserved: 2026-02-12T15:02:30.909Z

Link: CVE-2019-25340

cve-icon Vulnrichment

Updated: 2026-02-13T17:59:10.578Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-12T23:16:08.240

Modified: 2026-02-20T21:09:38.997

Link: CVE-2019-25340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-13T21:28:59Z

Weaknesses