Impact
A remote unauthenticated attacker can exploit AirSane by sending a crafted HTTP POST request containing an excessively large or malformed Content-Length header. The daemon’s custom HTTP server processes this unvalidated value directly in std::string::resize(), causing an allocation attempt for gigabytes of memory and resulting in a std::bad_alloc exception that crashes the service. The flaw also produces undefined behavior when non‑numeric characters appear in the header, but the impact remains limited to memory exhaustion and denial of service; it does not compromise confidentiality or integrity.
Affected Systems
The vulnerability affects all SimulPiscator AirSane installations running a version earlier than 0.4.12. The patch that validates the Content‑Length header and adds error handling was introduced in the 0.4.12 release, so any instance of AirSane prior to that version is susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate‑to‑high risk, while the EPSS score of less than 1% suggests that real‑world exploitation is low but not impossible. AirSane is an unprivileged service exposed over HTTP, so an attacker can reach it from any networked location without authentication; the low barrier to access increases the likelihood of an attempted exploit. Because the flaw manifests as a denial of service through memory exhaustion, an attacker can disrupt service availability, potentially affecting connected scanning workflows, but cannot achieve code execution or data exposure. The vulnerability is not listed in CISA’s KEV catalog, meaning no widespread, documented exploitation has been observed as of the current reporting.
OpenCVE Enrichment